Dernière minute
DEDeutschland erwartet brütende Hitze und Gewitter am FreitagDEGrüne kritisieren Bremse beim Ausbau des Hauptbahnhofs HannoverDEEU-Gipfel: Verärgerung über Alleingang von Ratspräsident Costa bei Russland-KontaktenDEMartha Argerich Festival Hamburg: Klassik trifft auf interdisziplinäre FormateDENachwahl in Makerfield: Keir Starmer droht parteiinterne Herausforderung durch Andy BurnhamDEFußball-WM 2026: Verletzungen, Kritik und ReisekostenDEBodensee: Felchenfang ab 2027 wieder erlaubt – aber mit strengen RegelnDEDFB-Haus in New York: Mehr als nur ein Ort für FußballfansDEDeutschlands kritische Infrastruktur: Nach Stromausfall in Reutlingen wird Debatte über Schutz neu entfachtDEG7-Staaten einigen sich auf mehr Zusammenarbeit bei kritischen RohstoffenDEDeutschland erwartet brütende Hitze und Gewitter am FreitagDEGrüne kritisieren Bremse beim Ausbau des Hauptbahnhofs HannoverDEEU-Gipfel: Verärgerung über Alleingang von Ratspräsident Costa bei Russland-KontaktenDEMartha Argerich Festival Hamburg: Klassik trifft auf interdisziplinäre FormateDENachwahl in Makerfield: Keir Starmer droht parteiinterne Herausforderung durch Andy BurnhamDEFußball-WM 2026: Verletzungen, Kritik und ReisekostenDEBodensee: Felchenfang ab 2027 wieder erlaubt – aber mit strengen RegelnDEDFB-Haus in New York: Mehr als nur ein Ort für FußballfansDEDeutschlands kritische Infrastruktur: Nach Stromausfall in Reutlingen wird Debatte über Schutz neu entfachtDEG7-Staaten einigen sich auf mehr Zusammenarbeit bei kritischen Rohstoffen
Newsgather
BackGitHub Confirms Cyberattack After Threat Actor Claims Data Sale
GitHub Confirms Cyberattack After Threat Actor Claims Data Sale
Urgent
Times of India20.05.2026Tech2 dk okumaIndia

GitHub Confirms Cyberattack After Threat Actor Claims Data Sale

L'essentiel

  • GitHub confirmed a cyberattack involving unauthorized access to internal repositories after a threat actor claimed to be selling company data.
  • The breach was linked to a poisoned VS Code extension on an employee device.

Résumé généré par IA

Pourquoi c'est important

GitHub has confirmed a cyberattack where a threat actor claimed to have stolen and was attempting to sell company data online. The incident involved unauthorized access to some of its internal repositories.

Taille de police

GitHub has confirmed a cyberattack involving unauthorized access to some of its internal repositories after a threat actor claimed it had stolen and was attempting to sell company data online. In a series of posts shared on X (formerly Twitter), the Microsoft-owned subsidiary said it has “detected and contained a compromise of an employee device involving a poisoned VS Code extension.” Github further said the malicious extension was removed, the affected endpoint was isolated and incident response measures were launched immediately. The platform also stated that its “current assessment is that the activity involved exfiltration of GitHub-internal repositories only,” while saying the attacker’s claims of accessing around 3,800 repositories are “directionally consistent” with the company’s investigation so far. The company said it has already rotated critical secrets and prioritised “highest-impact credentials” to reduce risk. GitHub also said it continues to analyse logs and monitor systems for additional suspicious activity.

Threat actor claims GitHub source code being sold

The incident became public after a threat actor known as TeamPCP allegedly listed GitHub source code and internal organisations for sale on a cybercrime forum. According to a report by The Hacker News, the group claimed to possess data from nearly 4,000 repositories and said the asking price was at least $50,000. Screenshots shared online reportedly showed the attackers saying: “We do not care about extorting GitHub. ” "As always, this is not a ransom," the group said in a post, according to screenshots shared by Dark Web Informer. "We do not care about extorting GitHub, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found, we leak it for free." The same threat group has also reportedly been linked to recent attacks involving malicious Python packages.

Attack linked to poisoned VS Code extension

GitHub has revealed that the breach was connected to a poisoned Microsoft Visual Studio Code extension installed on an employee device. “We removed the malicious extension version, isolated the endpoint, and began incident response immediately,” the company said. “We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants. We will publish a fuller report once the investigation is complete,” Github said in the post.

End of Article

Questions ouvertes

  • What specific internal repositories were accessed?
  • What is the full extent of the exfiltrated data?
  • How did the threat actor compromise the VS Code extension?
  • What are the long-term security implications for GitHub and its users?

Sujets liés

This article was originally published by Times of India.

Articles liés

Plus sur ce sujetcyberattack