TeamPCP Claims GitHub Source Code Breach
Key Takeaways The TeamPCP threat group claims to have breached GitHub’s internal systems, exfiltrating proprietary source code and data from approximately 4,000 private repositories. The...
Key Takeaways
- The TeamPCP threat group claims to have breached GitHub’s internal systems, exfiltrating proprietary source code and data from approximately 4,000 private repositories.
- The alleged stolen data is being offered for sale on cybercrime forums, with attackers seeking bids exceeding $50,000.
- GitHub has confirmed an ongoing investigation into unauthorized access to its internal repositories but states there is currently no evidence of impact to external customer data.
- TeamPCP, also tracked as UNC6780, is a highly active, financially motivated group known for sophisticated supply chain attacks, including recent compromises of Trivy, Checkmarx, and LiteLLM.
A prominent threat actor known as TeamPCP has asserted that it successfully infiltrated GitHub’s internal infrastructure, claiming to have stolen confidential organizational data and source code. The group is now attempting to monetize this alleged breach by offering the exfiltrated dataset for sale on dark web marketplaces, demanding bids upwards of $50,000.
Table Of Content
According to TeamPCP’s public statements on cybercrime forums, the compromised information includes data from approximately 4,000 private repositories directly linked to GitHub’s core platform. To substantiate these claims, the group has released a file list and screenshots purportedly showing various repository archive names and has offered to provide data samples to prospective buyers.
GitHub Responds to Claims
Following the emergence of these allegations, GitHub officially acknowledged an ongoing investigation. In a statement disseminated via X (formerly Twitter), the company confirmed unauthorized access to its internal repositories. However, GitHub sought to reassure its user base that, as of now, there is no indication that customer data stored outside these internal repositories has been affected.
GitHub stated, “We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.” The company also affirmed that it would notify customers through established incident response channels if any impact is discovered.
TeamPCP’s History of Sophisticated Attacks
TeamPCP is a financially motivated threat group formally identified by the Google Threat Intelligence Group (GTIG) as UNC6780. This group is recognized for its advanced capabilities and its track record of orchestrating severe cross-ecosystem supply chain attacks.
Earlier in 2026, TeamPCP was responsible for compromising several significant security and development tools:
- Trivy Vulnerability Scanner: The group exploited CVE-2026-33634, leading to the breach of over 1,000 organizations, including Cisco.
- Checkmarx and LiteLLM: These platforms were targeted in a rapid campaign focused on harvesting credentials within continuous integration/continuous delivery (CI/CD) pipelines.
- Shai-Hulud Malware: TeamPCP recently leaked the source code for its own Shai-Hulud malware directly onto GitHub, utilizing compromised accounts to do so.
The operational tactics employed by TeamPCP, which frequently involve leveraging stolen CI/CD credentials and privileged access tokens to penetrate deeper into target infrastructures, lend technical credibility to their recent claims against GitHub. The investigation is ongoing, and GitHub has not yet disclosed the method of alleged access nor has it confirmed the specific validity of the 4,000-repository claim. Further updates are anticipated as the inquiry progresses.
What You Should Do
- Monitor official GitHub communications for updates on the investigation.
- Review and strengthen access controls for all GitHub repositories, especially private ones, by implementing multi-factor authentication (MFA) and least privilege principles.
- Audit CI/CD pipeline configurations for any suspicious activity or unauthorized changes.
- Rotate credentials and API keys regularly, particularly those with access to sensitive GitHub resources.
- Educate development teams on phishing and social engineering tactics, as threat actors often target individual accounts to gain initial access.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.