Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitHub Confirms Breach of Internal Repos from Hacked Device
May 20, 2026
PoC Exploit Released for 20-Year Old PostgreSQL Vulnerability
May 20, 2026
ShinyHunters Cyber-Attack Hits Online Learning System
May 20, 2026
Home/CyberSecurity News/GitHub Confirms Breach of Internal Repos from Hacked Device
CyberSecurity News

GitHub Confirms Breach of Internal Repos from Hacked Device

GitHub has confirmed unauthorized access to its internal repositories, disclosing the incident in a series of official statements on May 20, 2026. The Microsoft-owned code hosting platform said it...

Emy Elsamnoudy
Emy Elsamnoudy
May 20, 2026 2 Min Read
2 0

GitHub has confirmed unauthorized access to its internal repositories, disclosing the incident in a series of official statements on May 20, 2026.

The Microsoft-owned code hosting platform said it identified and contained the breach after a poisoned VS Code extension was used to compromise an employee’s endpoint.

1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub’s internal repositories.

Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version,…

— GitHub (@github) May 20, 2026

GitHub immediately removed the malicious extension version, isolated the affected device, and activated its incident response procedures.

GitHub’s investigation indicates the attacker successfully exfiltrated data from GitHub-internal repositories only, with no confirmed impact on public or customer-hosted repositories at this stage.

The company stated that a threat actor’s claims of accessing approximately 3,800 repositories are “directionally consistent” with their findings so far.

2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

— GitHub (@github) May 20, 2026

A notorious threat actor operating under the alias TeamPCP has claimed responsibility for the breach, alleging the exfiltration of proprietary organization data and source code.

The group is reportedly offering the stolen dataset for sale on underground cybercrime forums, demanding offers exceeding $50,000. Their own claims cite roughly 4,000 private repositories tied directly to GitHub’s main platform.

GitHub moved quickly to reduce further exposure following initial detection. Key containment actions included:

  • Rotating critical secrets and credentials overnight, prioritizing highest-impact credentials first
  • Isolating the compromised employee endpoint
  • Removing the malicious VS Code extension version from circulation
  • Initiating continuous log analysis to detect any follow-on attacker activity

The use of a malicious VS Code extension as an initial access vector highlights a growing threat in developer-targeted supply chain attacks.

Threat actors increasingly target developer tooling, IDE extensions, CI/CD plugins, and package managers to gain footholds inside high-value technology organizations.

A trusted extension turning malicious can bypass traditional security controls and exfiltrate sensitive credentials or tokens silently in the background.

GitHub confirmed it continues to analyze logs, validate secret rotation completeness, and monitor for secondary activity.

4/ We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.

— GitHub (@github) May 20, 2026

The company stated it will take additional remediation actions as warranted by the investigation and has committed to publishing a fuller incident report once the review is complete.

GitHub has not confirmed any customer data exposure at this time.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

PoC Exploit Released for 20-Year Old PostgreSQL Vulnerability

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
macOS Malware Uses Fake Google Update for Persistence
May 19, 2026
Gentlemen Ransomware Hits Windows, Linux, NAS, Attacks ESXi
May 19, 2026
Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto
May 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us