Eilmeldung
ESAsesinato machista en Barcelona: Un marido asesina a su esposa tras denunciarla por maltratoESIncendio forestal en Fermoselle (Zamora): Evacuadas siete localidades y declarado el nivel máximo de gravedadESTerremoto en Japón: sube a 18 el número de muertos tras el sismo de magnitud 7,1 en KumamotoESIncendios en la Península Ibérica: Más de 115.000 personas evacuadas o confinadasESEl Rayo Vallecano en crisis: Denuncia por negar acceso a obras y dudas sobre el destino de 20 millones de eurosESAyuso anuncia 58 medidas para la recuperación del suroeste de Madrid tras el incendioESDetenido el propietario de la máquina que originó el incendio de Burgohondo, el mayor de la historia de EspañaESLa paz en Oriente Próximo: iniciativas para terminar la guerra entre EE.UU. e IránESJuez autoriza análisis de cuentas de Zapatero y su entorno por sospechas de blanqueoESIncendio en La Vall d'Uixó: Tania Baños describe los momentos más tensos y destaca la solidaridad ciudadanaESAsesinato machista en Barcelona: Un marido asesina a su esposa tras denunciarla por maltratoESIncendio forestal en Fermoselle (Zamora): Evacuadas siete localidades y declarado el nivel máximo de gravedadESTerremoto en Japón: sube a 18 el número de muertos tras el sismo de magnitud 7,1 en KumamotoESIncendios en la Península Ibérica: Más de 115.000 personas evacuadas o confinadasESEl Rayo Vallecano en crisis: Denuncia por negar acceso a obras y dudas sobre el destino de 20 millones de eurosESAyuso anuncia 58 medidas para la recuperación del suroeste de Madrid tras el incendioESDetenido el propietario de la máquina que originó el incendio de Burgohondo, el mayor de la historia de EspañaESLa paz en Oriente Próximo: iniciativas para terminar la guerra entre EE.UU. e IránESJuez autoriza análisis de cuentas de Zapatero y su entorno por sospechas de blanqueoESIncendio en La Vall d'Uixó: Tania Baños describe los momentos más tensos y destaca la solidaridad ciudadana
Newsgather
ZurückGitHub Investigates Unauthorized Access After Employee Device Compromise
GitHub Investigates Unauthorized Access After Employee Device Compromise
Dringend
Cointelegraph20.5.2026Technik2 Min. Lesezeit

GitHub Investigates Unauthorized Access After Employee Device Compromise

Auf einen Blick

  • GitHub is investigating unauthorized access to its internal repositories following a compromise of an employee's device via a poisoned VS Code extension.
  • A hacking group, TeamPCP, claims responsibility and is reportedly selling the data online.

KI-generierte Zusammenfassung

Schriftgröße

GitHub said on Wednesday it is investigating unauthorized access to its internal repositories following the compromise of an employee's device.

“While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories, we are closely monitoring our infrastructure for follow-on activity,” the developer platform said in a statement.

In a subsequent post, GitHub said it detected and contained a compromise of an employee device involving a poisoned VS Code extension on Tuesday. “We removed the malicious extension version, isolated the endpoint, and began incident response immediately,” it added.

GitHub is the go-to platform for developers, many of whom host their open source projects and repositories on its servers.

TeamPCP claims responsibility

Meanwhile, a hacking group called TeamPCP has reportedly claimed responsibility for the compromise and has attempted to sell the GitHub data online, claiming to have “4,000 repos of private code” related to GitHub’s main platform and internal organizations.

TeamPCP is a sophisticated, automation-heavy hacking group that turns compromised developer tools into credential-harvesting machines for financial gain, SecurityWeek reported.

TeamPCP claims responsibility on underground hacker forums. Source: Hackmanac

“If you have API keys in your code, even private repos, now is the time to double-check and change them,” Binance founder Changpeng Zhao said.

Related: Hackers used AI to craft zero-day attack to bypass 2FA: Google

It comes just a day after Grafana Labs, an open-source data observability company, said on Tuesday it was hit by a supply-chain attack in which malicious actors accessed its GitHub repositories and downloaded its codebase.

The attackers issued a ransom demand under threat of data disclosure, which the firm did not meet.

This incident also came shortly after the April 28 public disclosure of a critical remote code execution vulnerability, CVE-2026-3854, that allowed authenticated users to execute arbitrary commands on GitHub’s servers.

Wiz Research, which discovered the critical flaw, reported at the time that millions of public and private repositories belonging to other users and organizations were accessible on the affected nodes.

Verwandte Themen

This article was originally published by Cointelegraph.

Ähnliche Meldungen

Anthropic's AI Uncovers Vulnerabilities in Cryptographic Algorithms, Including US Federal Standard Contender HAWK
Technik·vor 19 Stunden

Anthropic's AI Uncovers Vulnerabilities in Cryptographic Algorithms, Including US Federal Standard Contender HAWK

Anthropic's AI model, Claude, discovered two previously unknown attacks on cryptographic algorithms: one against HAWK, a post-quantum digital signature scheme competing for US federal standard status, and another against a research version of AES. The HAWK vulnerability significantly reduces the security margin, potentially impacting its competitiveness due to required key size increases, while the AES attack demonstrates a novel approach though against a non-standard configuration.

Decrypt
5 Min. Lesezeit
Mehr zu diesem Themagithub