Mark RadarMARK RADAR
EN
Event File AI GitHub

GitHub Breach Exposes Source Code From 3,800 Internal Repositories

2 reports · First detected 2026-05-20 · Last active 2026-05-25

GitHub, one of the world’s leading code-hosting platforms, was hit by a software supply-chain attack after a malicious VS Code extension was installed on an employee device. The incident exposed source code from about 3,800 internal private repositories. It involved information about internal systems, but there is currently no evidence that customer data was affected.

GitHub confirmed on May 25 that code from its internal repositories had been leaked and said it was investigating unauthorized access. Hacker group TeamPCP claimed responsibility and attempted to sell the stolen data online. GitHub has removed the malicious packages and is continuing to determine the scope of the incident. It has not disclosed any transaction amount or asking price for the data.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)