GitHub Confirms Breach of Internal Repositories After Employee Device Compromised Via Malicious VS Code Extension
GitHub confirmed on May 20 that an employee's device was compromised through a poisoned VS Code extension, with exfiltration limited to internal repositories and no customer data affected
The structural exposure is not GitHub's intrusion but whether any of the estimated 6,000-plus installs of the malicious Nx Console version produced downstream compromise at other organizations, a question GitHub's containment leaves entirely unresolved, per reporting corroborated across three independent outlets. A poisoned maintainer account becoming a marketplace-wide distribution channel is the chokepoint TeamPCP appears to be systematically mapping across npm, PyPI, Docker, and now the VS Code Marketplace. Security teams at organizations whose developers ran Nx Console during the exposure window should treat this as a potential indicator of compromise against their own environments. The 3,800-repository figure may reflect metadata harvesting rather than full source code exfiltration, which would reduce its value to any prospective buyer.
4 sources
- GitHub Confirms Breach of Internal Repositories Via Hacked Employee Device -
Cyber Security News - GitHub confirms breach of 3,800 repos via malicious VSCode extension -
BleepingComputer - GitHub confirms being hacked by TeamPCP, says customer data unaffected -
The Record by Recorded Future - GitHub says internal repositories were impacted in poisoned VS Code extension attack -
CyberScoop