TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

GitHub Confirms Hackers Stole Data From About 3,800 Internal Repositories

Paul Balo by Paul Balo
May 20, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • GitHub has confirmed it was hacked, with attackers stealing data from roughly 3,800 of its internal code repositories.
  • The Microsoft-owned developer platform disclosed the incident in posts on X, saying it is still investigating the scope and impact of the breach.
  • According to GitHub, there is currently “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” though the company stressed that its investigation...

GitHub has confirmed it was hacked, with attackers stealing data from roughly 3,800 of its internal code repositories. The Microsoft-owned developer platform disclosed the incident in posts on X, saying it is still investigating the scope and impact of the breach.

According to GitHub, there is currently “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” though the company stressed that its investigation remains ongoing.

GitHub said it detected and contained a compromise involving an employee device that was infected through a “poisoned” Visual Studio Code (VS Code) extension. VS Code is a widely used code editor, and its ecosystem of extensions is a key part of many developers’ workflows.

The company described the poisoned extension as the initial vector that allowed attackers to access internal systems and exfiltrate data from thousands of internal repositories. GitHub has not yet publicly detailed what specific data was taken from those repositories.

The incident underscores a growing trend in software supply chain attacks, where threat actors target popular open-source tools and extensions to reach large numbers of developers at once. By compromising a widely used component, attackers can potentially infiltrate many downstream systems and projects in a single campaign.

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely…

— GitHub (@github) May 19, 2026

Also worth reading
Apple’s EU App Store Changes Still Leave Developers Paying For Access Hackers Abuse Microsoft Password Reset to Steal Data Hackers Tricked Meta’s AI Chatbot For Access Privileges To Instagram Accounts Over 185,000 Affected By 7-Eleven Data Breach KongTuke Hackers Exploits Microsoft Teams To Breach Companies OpenAI Confirms Hack Linked to TanStack Attack

Security outlets The Record and Bleeping Computer report that a hacking group known as TeamPCP has claimed responsibility for the GitHub breach and is attempting to sell the stolen data on a cybercrime forum. GitHub has not commented publicly on the group’s claims or on whether it has received any direct communication from the attackers, such as ransom demands.

TeamPCP has previously taken credit for a breach at the European Commission that led to the theft of more than 90 gigabytes of data from the EU executive’s cloud storage. According to those reports, the group obtained the European Commission’s cloud key during an earlier compromise of Trivy, a vulnerability scanning tool. Attackers reportedly pushed infostealing malware to Trivy’s downstream users, demonstrating how a single compromised tool can cascade into larger institutional breaches.

A similar pattern has emerged in another recent incident involving OpenAI. In that separate case, hackers targeted TanStack, a platform used by web developers, and pushed malicious updates designed to steal passwords and tokens from users. Like the VS Code extension compromise affecting GitHub, the TanStack incident shows how attackers are increasingly focusing on developer tooling as an entry point into high-value environments.

These cases reflect a broader shift in attacker strategy:

  • Compromising open-source or widely used developer tools to reach many targets at once.
  • Embedding malware in extensions, libraries, or updates that developers trust and routinely install.
  • Using stolen credentials, tokens or keys obtained through these tools to move into cloud environments and internal systems.

GitHub, a central hub for developers and open-source projects worldwide, is a particularly attractive target in this landscape. Any compromise of its internal systems naturally raises concerns about potential knock-on effects for the broader software ecosystem, even as GitHub says it has not seen evidence that customer data outside its internal repositories was affected.

At the time of publication, GitHub had not responded to questions about the incident beyond its statements on X, including whether it is in contact with TeamPCP or has received any extortion or ransom demands related to the theft.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • 1738537437848
    ChatGPT Deep Research Now Links to GitHub Repos
  • Screenshot 2024-10-03 at 15.34.40
    GitHub Copilot Surpasses 15 Million Users
  • xr:d:DAF04WpKy7A:2,j:5337175547361922434,t:23112209
    OpenAI Reportedly Building GitHub Rival Despite…
  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • AI_Risks-ChatGPT
    OpenAI Confirms Hack Linked to TanStack Attack
  • Gemini-Gems-cover
    Google Gemini Advanced Users Can Now Link to GitHub
  • microsoft-ceo-says-up-to-30-of-the-companys-code-was-v0-ecHugsZYFVGBlu0aBnbX0dxkhZ1KM6Gd5QaXUFybX58
    Microsoft CEO Says AI Now Writes Up to 30% of Company Code
  • ms claude
    Microsoft Initiates Claude Code Licenses Termination
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: code repodevelopersgithubhackerssecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Rivian Spinout ALSO Turns E-Bikes Into An Autonomous Delivery Bet August 23, 2026
  • Apple’s Foldable iPhone May Be Real, But The Trade-Offs Are Too August 23, 2026
  • Apple Job Cuts Point To A New Siri And Vision Pro Reset August 22, 2026
  • TikTok’s $400M Privacy Settlement Shows Child Safety Costs Are Rising August 22, 2026
  • OpenAI Cuts GPT-5.6 Sol API Prices As AI Price War Deepens August 22, 2026
  • Apollo Data Breach Shows Wall Street’s Cloud Security Problem August 21, 2026
  • Tesla’s China Recall Turns Hidden Door Handles Into A Safety Issue August 21, 2026
  • Oura Lawsuit Puts AI Sleep Tracking Under Legal Pressure August 21, 2026
  • Ericsson And MTN Move MoMo Onto Cloud Across Four Markets August 21, 2026
  • Kenya’s Digital ID Talks Put Trust Back At The Centre August 21, 2026
  • Starcloud’s $250M Raise Pushes Orbital AI Data Centres Closer August 21, 2026
  • Micron’s $10B Boise Lab Makes Memory A Bigger AI Battleground August 21, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.