عاجل
ESIrán cierra el Estrecho de Ormuz en respuesta a ataques israelíes en LíbanoESEspaña se prepara para la ola de calor más cálida de junio desde 1950ESColombia: El duelo entre el miedo y la rabia define la segunda vuelta presidencialESIván Cepeda: "De la Espriella es autoritario, amigo de la violencia y contrario al Estado de derecho"ESEspaña atrae a miles de perfiles de alto valor económico con una 'alfombra roja' migratoriaESIrlanda: La paradoja de un PIB en caída libre y una economía real boyanteESLamine Yamal: "He ganado todo lo que tengo jugando al fútbol"ESLa alianza de seguridad de EE.UU. con el Golfo Pérsico se agrieta por la guerra con IránESAnulación del registro de viviendas turísticas: un revés para las ciudades y el turismo españolESXi Jinping: El pozo que revela al líder chinoESIrán cierra el Estrecho de Ormuz en respuesta a ataques israelíes en LíbanoESEspaña se prepara para la ola de calor más cálida de junio desde 1950ESColombia: El duelo entre el miedo y la rabia define la segunda vuelta presidencialESIván Cepeda: "De la Espriella es autoritario, amigo de la violencia y contrario al Estado de derecho"ESEspaña atrae a miles de perfiles de alto valor económico con una 'alfombra roja' migratoriaESIrlanda: La paradoja de un PIB en caída libre y una economía real boyanteESLamine Yamal: "He ganado todo lo que tengo jugando al fútbol"ESLa alianza de seguridad de EE.UU. con el Golfo Pérsico se agrieta por la guerra con IránESAnulación del registro de viviendas turísticas: un revés para las ciudades y el turismo españolESXi Jinping: El pozo que revela al líder chino
Newsgather
BackGitHub Hacked, 3,800 Internal Code Repositories Compromised
GitHub Hacked, 3,800 Internal Code Repositories Compromised
مُلِح
TechCrunch20.05.2026تقنية2 dk okumaUnited States

GitHub Hacked, 3,800 Internal Code Repositories Compromised

نظرة سريعة

  • GitHub confirmed a hack affecting 3,800 internal code repositories.
  • Attackers used a poisoned VS Code extension to compromise an employee device.
  • The group TeamPCP claimed responsibility and is selling the data.

ملخص مُنشأ بالذكاء الاصطناعي

لماذا يهم

Hackers are increasingly targeting popular open-source projects, including coding extensions, to compromise developers' computers and projects. This strategy allows them to access a large number of computers simultaneously, amplifying the impact of their attacks. The group TeamPCP has a history of similar breaches, including one at the European Commission.

حجم الخط

GitHub, the popular developer platform owned by Microsoft, confirmed it was hacked and attackers had stolen data from around 3,800 internal code repositories.

The code hosting and sharing giant said in a series of posts on X that it has “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” but noted its investigation was ongoing. GitHub said it “detected and contained a compromise of an employee device involving a poisoned VS Code extension,” referring to a plug-in for Visual Studio Code, a popular code editor that developers use for programming.

Hackers are increasingly targeting popular open source projects, including coding extensions, with the aim of compromising developers’ computers and their projects. Targeting popular projects allows hackers to gain access to vast numbers of computers at the same time, magnifying the impact of their attacks.

GitHub did not name the compromised extension.

The Record and Bleeping Computer report that a hacking group called TeamPCP has taken credit for the GitHub breach and is selling the data on a cybercrime forum.

GitHub did not immediately respond to a request for comment about the incident, or answer questions on whether it has received any communication from the hackers, such as a demand for ransom.

TeamPCP previously claimed credit for a data breach at the European Commission that resulted in the theft of more than 90 gigabytes of data from the cloud storage of the EU’s executive arm. The hackers had stolen the European Commission’s cloud key during an earlier breach at Trivy, a vulnerability scanning tool, by pushing info-stealing malware to Trivy’s downstream users.

أسئلة مفتوحة

  • Which specific VS Code extension was compromised?
  • What is the exact nature and sensitivity of the stolen code?
  • Has GitHub received any ransom demands from TeamPCP?
  • What specific security measures are being implemented to prevent future attacks?

مواضيع ذات صلة

This article was originally published by TechCrunch.

أخبار ذات صلة

Apple Unveils Numerous App and Service Upgrades at WWDC Beyond Siri
يتطور·13 sa önce

Apple Unveils Numerous App and Service Upgrades at WWDC Beyond Siri

Apple announced significant updates to its core apps and services at WWDC, including enhanced Apple Maps with 'Local Lists' and improved 'Flyover,' more flexible location sharing in Find My, and advanced bill splitting in Apple Wallet powered by Apple Intelligence. Other updates include redesigned Apple Pay checkout, expanded Apple Music features like lyrics translation, new search capabilities in Apple Podcasts, improved iCloud Shared Albums, and a new Fitness+ program for menopause.

TechCrunch
المزيد حول هذا الموضوعgithub