www.darkreading.com 5/20/2026, 8:50:28 PM · external

GitHub Hit by Data Theft After VS Code Extension Compromise

GitHub Hit by Data Theft After VS Code Extension Compromise
CyberSIXT Evidence Panel
Primary Source x.com
Threat Actor

GITHUB confirmed a data breach involving the theft of approximately 4,000 internal repositories by a threat actor known as TeamPCP. The breach was reportedly facilitated through a compromised Visual Studio Code extension. GitHub detected and isolated the issue, rotating critical credentials and initiating an investigation. TeamPCP claims it would sell the stolen data but would leak it for free if no buyer is found. Experts highlighted the vulnerabilities associated with developer tools and the trust model in software security.

View Primary Source Via www.darkreading.com

Article by CyberSIXT