Piece of news of the day

ADVANCED SECURITY EUROPA

EOOD

Code Red: GitHub Breach Exposes 3,800 Internal Repositories Due to Malicious VS Code Extension

20 May 2026

GitHub confirmed a breach in which 3,800 internal repositories were compromised due to a malicious VS Code extension installed by an employee.
The trojanized extension was removed, and the affected device secured.
The breach involved exfiltration of GitHub-internal repositories, with hacker group TeamPCP claiming access to GitHub source code and private code repositories.
VS Code extensions have been targeted in the past for stealing developer credentials, with malicious extensions posing as legitimate tools.
GitHub, used by over 4 million organizations and 180 million developers, is investigating the breach and working to secure its platform.