GitHub Internal Repositories Accessed Without Authorization, Raising Crypto Supply-Chain Concerns
Microsoft-owned GitHub is a major code-hosting platform used by many cryptocurrency and Web3 projects to manage source code, CI/CD pipelines and package releases. If developer devices or the extension supply chain are compromised, attackers could steal access tokens, signing keys and private keys, or inject malicious updates. The incident therefore extends beyond GitHub’s internal code and highlights systemic software supply-chain risks.
A malicious version of the Nx Console VS Code extension, 18.95.0, was available for about 18 minutes on May 18, 2026. GitHub confirmed on May 20 that an employee device had been compromised and about 3,800 internal repositories exposed. TeamPCP was reportedly offering the data for $50,000. GitHub removed the malicious release, isolated the device and rotated credentials, saying it had found no evidence that customer data was affected.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →