• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

GitHub Confirms Hackers Stole Data From About 3,800 Internal Repositories

Paul Balo by Paul Balo
May 20, 2026
in Security
Share on FacebookShare on Twitter

GitHub has confirmed it was hacked, with attackers stealing data from roughly 3,800 of its internal code repositories. The Microsoft-owned developer platform disclosed the incident in posts on X, saying it is still investigating the scope and impact of the breach.

According to GitHub, there is currently “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” though the company stressed that its investigation remains ongoing.

GitHub said it detected and contained a compromise involving an employee device that was infected through a “poisoned” Visual Studio Code (VS Code) extension. VS Code is a widely used code editor, and its ecosystem of extensions is a key part of many developers’ workflows.

The company described the poisoned extension as the initial vector that allowed attackers to access internal systems and exfiltrate data from thousands of internal repositories. GitHub has not yet publicly detailed what specific data was taken from those repositories.

The incident underscores a growing trend in software supply chain attacks, where threat actors target popular open-source tools and extensions to reach large numbers of developers at once. By compromising a widely used component, attackers can potentially infiltrate many downstream systems and projects in a single campaign.

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely…

— GitHub (@github) May 19, 2026

Security outlets The Record and Bleeping Computer report that a hacking group known as TeamPCP has claimed responsibility for the GitHub breach and is attempting to sell the stolen data on a cybercrime forum. GitHub has not commented publicly on the group’s claims or on whether it has received any direct communication from the attackers, such as ransom demands.

TeamPCP has previously taken credit for a breach at the European Commission that led to the theft of more than 90 gigabytes of data from the EU executive’s cloud storage. According to those reports, the group obtained the European Commission’s cloud key during an earlier compromise of Trivy, a vulnerability scanning tool. Attackers reportedly pushed infostealing malware to Trivy’s downstream users, demonstrating how a single compromised tool can cascade into larger institutional breaches.

A similar pattern has emerged in another recent incident involving OpenAI. In that separate case, hackers targeted TanStack, a platform used by web developers, and pushed malicious updates designed to steal passwords and tokens from users. Like the VS Code extension compromise affecting GitHub, the TanStack incident shows how attackers are increasingly focusing on developer tooling as an entry point into high-value environments.

These cases reflect a broader shift in attacker strategy:

  • Compromising open-source or widely used developer tools to reach many targets at once.
  • Embedding malware in extensions, libraries, or updates that developers trust and routinely install.
  • Using stolen credentials, tokens or keys obtained through these tools to move into cloud environments and internal systems.

GitHub, a central hub for developers and open-source projects worldwide, is a particularly attractive target in this landscape. Any compromise of its internal systems naturally raises concerns about potential knock-on effects for the broader software ecosystem, even as GitHub says it has not seen evidence that customer data outside its internal repositories was affected.

At the time of publication, GitHub had not responded to questions about the incident beyond its statements on X, including whether it is in contact with TeamPCP or has received any extortion or ransom demands related to the theft.

Related Posts:

  • 1738537437848
    ChatGPT Deep Research Now Links to GitHub Repos
  • Screenshot 2024-10-03 at 15.34.40
    GitHub Copilot Surpasses 15 Million Users
  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • xr:d:DAF04WpKy7A:2,j:5337175547361922434,t:23112209
    OpenAI Reportedly Building GitHub Rival Despite…
  • AI_Risks-ChatGPT
    OpenAI Confirms Hack Linked to TanStack Attack
  • Gemini-Gems-cover
    Google Gemini Advanced Users Can Now Link to GitHub
  • microsoft-ceo-says-up-to-30-of-the-companys-code-was-v0-ecHugsZYFVGBlu0aBnbX0dxkhZ1KM6Gd5QaXUFybX58
    Microsoft CEO Says AI Now Writes Up to 30% of Company Code
  • ms claude
    Microsoft Initiates Claude Code Licenses Termination

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: code repodevelopersgithubhackerssecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • GitHub Confirms Hackers Stole Data From About 3,800 Internal Repositories May 20, 2026
  • Google’s AI Studio Can Now Spin Up Native Android Apps in Minutes May 20, 2026
  • YouTube Tests ‘Ask YouTube’ AI Search and Brings Gemini Omni to Shorts Creation May 20, 2026
  • Google Launches Gemini Omni Flash to Turn Any Input Into AI-Generated Video May 20, 2026
  • Figma Brings AI Assistant Directly Into Its Collaborative Canvas May 20, 2026
  • The Google Search You Know Is Gone and Its Ok May 20, 2026
  • Fortnite Returns to iPhone, iPad App Store May 20, 2026
  • Google Staked As Major Contender In AI Designs At I/O 2026 May 20, 2026
  • Google Takes On ChatGPT & Claude With Gemini App Update at I/O 2026 May 20, 2026
  • Google Says Gemini 3.5 Flash Can Rival Flagship AI Models on Coding and Agents May 19, 2026
  • Google Turns Its Search Box Into An AI Entry Point After 25 Years May 19, 2026
  • One in Five Brits Fear AI Layoffs Could Spark Civil Unrest, Study Finds May 19, 2026

Browse Archives

May 2026
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.