Gen. partnerAlgotech

GitHub confirmed compromise of internal repositories after attack via malicious VS Code extension

GitHub said it detected the attack and subsequently limited its impact. According to the company, an employee's device was compromised, on which a malicious VS Code extension had been installed.

|
May 20, 2026
GitHub confirmed compromise of internal repositories after attack via malicious VS Code extension

The company GitHub confirmed a security incident in which internal repositories were exfiltrated after an employee's device was compromised via a malicious extension for Visual Studio Code. The firm said that, according to the current assessment, the incident concerns only the company's internal repositories and there is so far no evidence of compromise of customer data outside the affected systems.

Employee device compromise via VS Code extension

GitHub said it detected the attack and subsequently limited its impact. According to the company, an employee's device was compromised, on which a malicious VS Code extension had been installed.

The company removed the compromised version of the extension from the marketplace, isolated the affected endpoint, and launched an internal investigation of the incident. At the same time, it rotated critical secrets and credentials with the highest impact.

GitHub is also continuing to analyze logs and monitor for any follow-up activities by the attackers.

Approximately 3 800 repositories and the TeamPCP group

Shortly after the incident was disclosed, claims by the group TeamPCP appeared on cybercrime forums, allegedly offering data obtained from GitHub's internal repositories.

The attackers claim to have gained access to approximately 3 800 internal repositories. GitHub has not publicly confirmed that number but called it „directionally consistent“ with the ongoing investigation.

The company also did not comment on the alleged sale of the data or threats to publish it if a buyer is not found.

The TeamPCP group has in recent months been associated with attacks targeting the software supply chain, open-source packages, and developer tools.

The investigation also involves Nx Console

GitHub has not publicly named the specific VS Code extension that was used in the attack. However, the extension Nx Console has also become part of the publicly discussed investigation.

A security advisory around the Nx project states that the project's maintainer was compromised and his GitHub credentials were leaked. Using those credentials, a malicious version of the extension was allegedly then uploaded to the VS Code Marketplace.

NX said it is working with Microsoft to determine the full scope of the incident. Some estimates talk about thousands of installations of the compromised package, though those numbers have not yet been publicly confirmed.

VS Code extensions as a new supply-chain problem

The incident again shows how significant a security risk VS Code extensions and other developer tools are becoming.

Extensions often have access to source code, tokens, SSH keys, or cloud credentials stored directly on developers' machines. That is why they represent an attractive target for supply-chain attacks.

Security experts have long warned that control over which extensions and packages run on developers' devices is often significantly weaker in companies than for regular endpoints.

GitHub said it will publish a more detailed technical report on the incident once the investigation is complete.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.