INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitHub confirms breach of 3,800 repos via malicious VSCode

| 2026-05-20 08:14 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A malicious VS Code extension, allegedly created by WhiteCobra, was installed on GitHub's platform after flooding the marketplace with 24 crypto-stealing extensions. The extension, which had basic ransomware capabilities and was later removed from the market, breached approximately 3,800 internal repositories, exfiltrating data only. This incident is part of a larger pattern of malicious VS Code extensions being used to steal developer credentials and sensitive data, as seen in previous incidents involving millions of installs. The attack works by exploiting vulnerabilities in the extension's code, allowing attackers to gain access to GitHub's internal systems. As of now, GitHub has secured the compromised device and is conducting an incident response, but no evidence suggests that customer data stored outside the affected repositories was impacted.
Technical Mitigations AI-generated
• Remove or update the malicious VSCode extension from your system immediately. • Monitor for and block any suspicious activity related to TeamPCP, including indicators of compromise such as unusual API calls or unauthorized access attempts on GitHub repositories. • Regularly scan your systems for XMRig cryptominer infections.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/05/20
Threat actors used a malicious VSCode extension to target GitHub, resulting in the breach of approximately 3,800 internal repositories.
infrastructure 1.5 installs
infrastructure Vs Code
infrastructure 9 installs
victims 4 organizations
Tactical Metrics
Metrics
infrastructure
1,500,000
Installs
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
9,000,000
Installs
Metrics
victims
4,000,000
Organizations
Intelligence Sources