Inside the GitHub Breach: The suspicious extension that exposed internal repositories and what went wrong
GitHub has contained a breach involving unauthorized access to thousands of internal repositories, allegedly linked to a malicious VS Code extension and claimed by the Team PCP hacking group

Microsoft’s software platform GitHub has confirmed that a third party recently gained unauthorized access to 3,800 internal repositories. The breach was detected on May 19 and is believed to be a downstream effect of a malicious Visual Studio Code extension found by the GitHub security team on an employee’s device, as confirmed by GitHub on social media.
Visual Studio Code is a free-to-use, open-source code editor developed by Microsoft. It is often used alongside GitHub Copilot, an AI-powered coding assistant.
The breach has been claimed by the Team PCP hacking group. The group posted on the Breached cybercrime forum, alleging that they gained access to GitHub source code and “400 repos of private code.” Team PCP is reportedly demanding at least $50,000 for the stolen data, and has threatened to leak the data publicly if its demands are not met.
GitHub has confirmed that it has now contained the breach. “We removed the malicious extension version, isolated the endpoint, and began incident response immediately. Critical secrets were rotated yesterday and overnight, with the highest-impact credentials prioritized first,” the company said. “We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.”
Team PCP's Modus Operandi
The PCP cyber threat group has gained traction for conducting large-scale software supply chain attacks, particularly targeting open-source ecosystems and security-adjacent tools. The group has previously compromised widely used projects such as the Trivy vulnerability scanner and KICS (Infrastructure as Code analyzer) through attacks on GitHub Actions and other software development pipelines.
After these incidents, the group expanded its campaign to the Python Package Index, where it reportedly compromised legitimate packages, including the LiteLLM AI gateway client library and Telnyx’s official SDK, by publishing backdoored releases. Beyond these compromises, it has also used typosquatting and other deceptive techniques to distribute credential-stealing malware.
These attacks have been aimed at extracting sensitive information such as cloud credentials, SSH keys, Kubernetes configurations, and other development secrets from multiple organizations.
Team PCP has reportedly been exploring ways to monetize the stolen data obtained through these campaigns. At the same time, a new threat framework dubbed “PCP Jack” has emerged, designed to detect and remove Team PCP artifacts from compromised environments while also moving laterally to capture additional cloud credentials. This highlights the increasingly competitive and fast-evolving nature of cloud-focused cybercrime ecosystems linked to the group’s activities.

OpenAI launches Presence to bring AI agents into customer support and enterprise workflows
Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
