GitHub confirmed that attackers exfiltrated about 3,800 internal repositories after compromising an employee device with a trojanized Visual Studio Code extension, later identified in multiple reports as Nx Console 18.95.0. The company said the malicious extension was removed, the affected endpoint was isolated, critical secrets and credentials were rotated, and incident response, log analysis, and follow-on monitoring were launched. GitHub’s current assessment is that the intrusion was limited to GitHub-internal repositories, with no evidence that customer repositories, enterprise accounts, or data stored outside those repositories were broadly affected, though some internal repositories may contain limited customer-related support information.
The breach was widely attributed to TeamPCP (also tracked as UNC6780), which advertised the stolen source code and internal organizational data on cybercrime forums and leak sites for $50,000 to $95,000, threatening to publish it if unsold. Reporting tied the compromise to the broader TanStack supply-chain campaign and said the poisoned extension was briefly available on Visual Studio Marketplace and OpenVSX, carrying credential-stealing malware aimed at GitHub, npm, AWS, Kubernetes, 1Password, and other developer assets. GitHub later told GitHub Enterprise Server administrators to rotate GPG public keys as part of signing-key rotation, while government and industry alerts urged organizations to remove the malicious extension, rotate exposed developer credentials, and scrutinize CI/CD and repository activity for follow-on abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Canada's Cyber Centre published Alert AL26-013 about the GitHub incident, stating GitHub detected the intrusion on May 18 and attributing initial access to Nx Console version 18.95.0 on a compromised employee device. The alert advised removing the extension, rotating exposed credentials from the May 11–20 window, monitoring CI/CD activity, and following GitHub Enterprise Server key-rotation guidance.
GitHub told administrators of self-hosted GitHub Enterprise Server environments to rotate public encryption keys following the incident. The guidance reiterated that GitHub was rotating all keys, including the Enterprise Server signing key, while saying no evidence showed customer or enterprise repositories were compromised.
FINRA warned member firms about downstream risks from the GitHub breach and summarized GitHub's May 20 confirmation that about 3,800 internal repositories were affected. The alert urged increased monitoring, compensating controls, employee training, and reporting of suspicious activity to regulators and law enforcement.
Follow-up reporting said GitHub linked the breach to a malicious version of the Nx Console VS Code extension, tracing the compromise to the broader TanStack-related supply-chain attack. Reports also said the extension carried credential-stealing functionality targeting developer and cloud secrets.
GitHub published an investigation update requiring GitHub Enterprise Server administrators to rotate GPG public keys because the company was rotating keys, including the GitHub Enterprise Server signing key, as a precaution. GitHub Enterprise Cloud customers were told no action was required.
GitHub disclosed that attackers exfiltrated about 3,800 internal repositories after compromising an employee device through a poisoned Visual Studio Code extension. The company said its assessment indicated the activity was limited to GitHub-internal repositories and that it had no evidence customer data stored outside those repositories was affected.
After detecting the compromise, GitHub isolated the affected endpoint, removed the malicious extension version, launched incident response, and began rotating critical secrets and credentials. Some reporting specifies that secret rotation started Monday into Tuesday following discovery.
TeamPCP claimed on Breached/BreachForums that it had stolen roughly 4,000 private GitHub repositories, source code, and internal organizational data, offering the data for sale and threatening to leak it if unsold. One report explicitly dates the forum advertisement to May 19, 2026.
GitHub detected unauthorized access after a compromised employee device, infected via a malicious VS Code extension, was used to access and exfiltrate roughly 3,800 internal repositories. Multiple reports state the incident was detected on May 18 or May 19, with GitHub later tying the intrusion to its internal repositories only.
A trojanized Nx Console Visual Studio Code extension, version 18.95.0, was made available on Visual Studio Marketplace and OpenVSX for about 18 minutes. Reporting says this poisoned extension was the initial infection vector used against a GitHub employee device.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
39 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcesafestate.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceforbes.com
Open sourcebleepingcomputer.com
Open sourcereddit.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.