Eilmeldung
ARاعتقال رجل في اسكتلندا على خلفية هجمات معادية للإسلامARإيران تهدد بإغلاق مضيق هرمز وسط توترات مع إسرائيل وأمريكاARنائب مصري يحذر من تحول السيارات لأدوات قتل متنقلة بسبب قيادة الأطفالARتصعيد عسكري عنيف في لبنان: مقتل أكثر من 110 أشخاص وإدانات دوليةARمسيرة جماهيرية ضخمة في أتلانتا تحفيزاً للاعبي السعودية قبل مواجهة إسبانياARأسواق الصرف العالمية وسندات الدخل الثابت تترقب أسبوعاً حاسماً للسياسات النقديةARحمزة عبد الكريم: أصغر لاعبي مصر في كأس العالم ووريث محمد صلاح المحتملARمعرض "خټین زر" في هرات: نساء أفغانيات يحولن التراب إلى ذهب رغم قيود طالبانARإعادة هيكلة الطرق اللوجستية: الولايات المتحدة لاعب رئيسي جديد في إمدادات الطاقة لآسيا عبر القناةARهدوء حذر في جنوب لبنان بعد يومين داميينARاعتقال رجل في اسكتلندا على خلفية هجمات معادية للإسلامARإيران تهدد بإغلاق مضيق هرمز وسط توترات مع إسرائيل وأمريكاARنائب مصري يحذر من تحول السيارات لأدوات قتل متنقلة بسبب قيادة الأطفالARتصعيد عسكري عنيف في لبنان: مقتل أكثر من 110 أشخاص وإدانات دوليةARمسيرة جماهيرية ضخمة في أتلانتا تحفيزاً للاعبي السعودية قبل مواجهة إسبانياARأسواق الصرف العالمية وسندات الدخل الثابت تترقب أسبوعاً حاسماً للسياسات النقديةARحمزة عبد الكريم: أصغر لاعبي مصر في كأس العالم ووريث محمد صلاح المحتملARمعرض "خټین زر" في هرات: نساء أفغانيات يحولن التراب إلى ذهب رغم قيود طالبانARإعادة هيكلة الطرق اللوجستية: الولايات المتحدة لاعب رئيسي جديد في إمدادات الطاقة لآسيا عبر القناةARهدوء حذر في جنوب لبنان بعد يومين داميين
Newsgather
BackGitHub Employee's Malicious VS Code Extension Leads to Data Breach
GitHub Employee's Malicious VS Code Extension Leads to Data Breach
Dringend
Decrypt20.05.2026Technik2 dk okuma

GitHub Employee's Malicious VS Code Extension Leads to Data Breach

Auf einen Blick

  • GitHub confirmed a data breach affecting ~3,800 internal code repositories, caused by a malicious VS Code extension installed by an employee.
  • A hacker group, TeamPCP, claimed responsibility, seeking $50,000 for the data.

KI-generierte Zusammenfassung

Warum es wichtig ist

GitHub confirmed a data breach where a hacker group stole approximately 3,800 internal code repositories. The breach occurred after an employee installed a malicious Visual Studio Code extension, which was designed to exfiltrate data. GitHub stated that only internal repositories were affected and no customer data outside these repos was impacted.

Schriftgröße

GitHub confirmed Tuesday that a hacker group stole roughly 3,800 internal code repositories after one of its employees unknowingly installed a malicious Visual Studio Code extension.

VS Code extensions are plugins downloaded through Microsoft’s official marketplace that add features to the code editor. In this case, the extension was designed to exfiltrate data in the background.

“Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension,” the company said in a post on X. “We removed the malicious extension version, isolated the endpoint, and began incident response immediately.”

The Microsoft-owned GitHub is one of the largest software development platforms online, used by more than 180 million developers across over 4 million organizations, including 90% of the Fortune 100.

“Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only,” GithHub wrote. “The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.”

According to GitHub, the breach affected only internal repositories, and no customer data stored outside those repos was impacted.

"We have no evidence of impact to customer information stored outside of GitHub's internal repositories, such as our customer's own enterprises, organizations, and repositories,” a GitHub spokesperson told Decrypt. “Some of GitHub's internal repositories contain information from customers, for example, excerpts of support interactions. If any impact is discovered, we will notify customers via established incident response and notification channels."

The company said it rotated critical credentials overnight, prioritizing the highest-risk secrets first, and is continuing to monitor for additional activity.

According to cybersecurity X account Dark Web Informer, TeamPCP claimed responsibility for the breach on Breached, a black-hat cybercrime forum. The group allegedly said it possessed around 4,000 private repositories and was seeking at least $50,000 for the data, with samples available to verified buyers.

“This remains an unverified underground forum claim,” Dark Web Informer wrote. “The actor states this is not a ransom attempt and claims the data may be leaked publicly if no buyer is found.”

Offene Fragen

  • What specific types of information were contained within the exfiltrated internal repositories?
  • What is the exact timeline of the malicious extension's activity?
  • What measures will GitHub implement to prevent similar breaches in the future?
  • Has TeamPCP provided verifiable proof of the stolen data?

Verwandte Themen

This article was originally published by Decrypt.

Ähnliche Meldungen

ChatGPT Users Suspect OpenAI is A/B Testing GPT-5.6
In Entwicklung·1 g önce

ChatGPT Users Suspect OpenAI is A/B Testing GPT-5.6

ChatGPT users are reporting significant slowdowns and performance differences, leading to speculation that OpenAI is secretly A/B testing a new GPT-5.6 model. Developers are sharing screenshots and videos comparing generation times, with some tests showing much longer durations than the current GPT-5.5 Pro. Leaked details suggest improvements in reasoning and design generation, with a potential release date in late June.

Decrypt
Mehr zu diesem Themagithub