GitHub confirmed that attackers stole data from roughly 3,800 internal repositories after a malicious Visual Studio Code extension compromised an employee device; the company says it has no evidence that customer repo... The attack reportedly involved the hacking group TeamPCP, which claimed responsibility and alleg...

Create a landscape editorial hero image for this Studio Global article: What happened in the recent GitHub cyberattack where hackers reportedly stole data from about 3,800 internal repositories, how did the breac. Article summary: GitHub confirmed an incident in which attackers exfiltrated data from roughly 3,800 internal repositories after an employee device was compromised through a malicious Visual Studio Code extension [5]. GitHub said it curr. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "GitHub has confirmed that roughly 3800 internal repositories were hacked after an employee installed an infected VS Code extension." source context "GitHub Confirms Hack Impacting 3,800 Internal Repositories - SecurityWeek" Reference image 2: visual subject "A GitHub employee has unwittingly allowed 3800 internal
GitHub confirmed in May 2026 that attackers exfiltrated data from approximately 3,800 internal repositories after compromising an employee’s development machine. The breach began when a trojanized Visual Studio Code extension was installed on the device, giving the attacker a foothold inside GitHub’s internal environment.
According to GitHub’s investigation, the malicious extension allowed the attacker to access and clone internal repositories used by the company itself. Once detected, GitHub said it removed the malicious extension version, isolated the compromised endpoint, and initiated an incident‑response investigation.
While the number of repositories involved is large, the company emphasized that the incident affected internal code repositories rather than customer repositories hosted on the platform.
The entry point was a poisoned extension for Visual Studio Code (VS Code)—a widely used code editor in the developer ecosystem.
Investigators say the extension was installed on a GitHub employee’s machine, which allowed attackers to compromise the device and access internal systems. From there, the attackers reportedly cloned thousands of internal repositories associated with GitHub’s own infrastructure and development processes.
GitHub stated that it:
The company’s current assessment is that the attacker activity resulted in the exfiltration of internal GitHub repositories only.
GitHub’s public statements stressed that there is currently no evidence that customer repositories or user data stored outside GitHub’s internal systems were affected.
That means:
However, the company noted that the investigation is ongoing and that it continues to monitor for any follow‑on activity.
A threat actor calling itself TeamPCP claimed responsibility for the breach. The group allegedly posted on a cybercrime forum advertising access to GitHub’s internal code and organizational data.
Some cybersecurity researchers have linked the group to the threat cluster UNC6780, though attribution details remain tentative and have not been fully confirmed by GitHub.
Reports suggest the attackers attempted to sell the stolen data for tens of thousands of dollars on underground marketplaces.
Beyond the immediate breach, the incident highlights a larger trend: attackers increasingly target developer tools and software supply chains rather than production systems directly.
Developer ecosystems—such as:
have become high‑value targets because compromising a trusted tool can potentially give attackers access to many downstream systems.
Security research shows that these attacks are accelerating. For example, industry analysis has documented large numbers of malicious open‑source packages and sustained campaigns targeting developer environments and CI/CD pipelines.
In other words, attackers increasingly exploit the trust developers place in widely used tooling.
The breach reinforces several security practices for organizations that rely heavily on developer tooling:
Developer machines often have privileged access to repositories, build pipelines, and secrets. When a developer tool becomes compromised, attackers can potentially reach far deeper into a company’s infrastructure than through traditional attacks.
The GitHub incident is a reminder that modern software security increasingly depends on protecting the tools developers use every day. As attackers shift toward supply‑chain compromises and malicious extensions, even trusted components of the development workflow can become entry points into large technology platforms.
While GitHub says customer data has not been affected so far, the attack underscores how a single compromised extension can expose critical internal systems—and why securing the developer ecosystem has become a top cybersecurity priority.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
GitHub confirmed that attackers stole data from roughly 3,800 internal repositories after a malicious Visual Studio Code extension compromised an employee device; the company says it has no evidence that customer repo...
GitHub confirmed that attackers stole data from roughly 3,800 internal repositories after a malicious Visual Studio Code extension compromised an employee device; the company says it has no evidence that customer repo... The attack reportedly involved the hacking group TeamPCP, which claimed responsibility and allegedly offered the stolen data for sale on a cybercrime forum.
Security experts say the breach reflects a growing pattern of supply‑chain attacks targeting developer tools, extensions, and open‑source ecosystems used across modern software development.