Mark RadarMARK RADAR
About
EN
Sign in

GitHub Internal Repositories Accessed Without Authorization, Raising Crypto Supply-Chain Concerns

2 reports · First detected 2026-05-20 · Last active 2026-05-21

Microsoft-owned GitHub is a major code-hosting platform used by many cryptocurrency and Web3 projects to manage source code, CI/CD pipelines and package releases. If developer devices or the extension supply chain are compromised, attackers could steal access tokens, signing keys and private keys, or inject malicious updates. The incident therefore extends beyond GitHub’s internal code and highlights systemic software supply-chain risks.

A malicious version of the Nx Console VS Code extension, 18.95.0, was available for about 18 minutes on May 18, 2026. GitHub confirmed on May 20 that an employee device had been compromised and about 3,800 internal repositories exposed. TeamPCP was reportedly offering the data for $50,000. GitHub removed the malicious release, isolated the device and rotated credentials, saying it had found no evidence that customer data was affected.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)