GitHub: 3,800 Internal Repos Hacked via VS Code Plugin

SkimNews Take
The AI's ability to "formulate hypotheses" suggests a move beyond mere pattern recognition, enabling it to propose novel explanations and pathways for drug repurposing, rather than just identifying correlations.
Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- GitHub confirmed that roughly 3,800 internal repositories were breached after an employee installed a malicious VS Code extension, per BleepingComputer
- TeamPCP claimed responsibility for the breach and reportedly attempted to sell the stolen source code for $50,000, according to Forbes
- GitHub stated that customer repositories and customer data were unaffected by the incident, as reported by The Record
- The breach originated from a single poisoned VS Code extension, turning one employee's careless install into mass internal source-code exfiltration
- Coverage was near-universal across security outlets (Security Affairs, SecurityWeek, Metacurity), tech press (TechCrunch, The Register, Tom's Hardware), and crypto-focused publications flagging developer supply-chain exposure
- Binance's Changpeng Zhao publicly urged caution on X, warning users to rotate API keys and credentials in the breach's aftermath
Why it matters: One employee's malicious VS Code extension exposed ~3,800 internal GitHub repos while customer data stayed untouched, with TeamPCP attempting a $50,000 ransom sale. The incident demonstrates how a single poisoned plugin on a developer's machine can cascade into mass internal source-code exfiltration, giving attacker groups a confirmed monetization playbook for supply-chain campaigns.
Ask SkimNews



