GitHub Breach Exposes Source Code From 3,800 Internal Repositories
GitHub, one of the world’s leading code-hosting platforms, was hit by a software supply-chain attack after a malicious VS Code extension was installed on an employee device. The incident exposed source code from about 3,800 internal private repositories. It involved information about internal systems, but there is currently no evidence that customer data was affected.
GitHub confirmed on May 25 that code from its internal repositories had been leaked and said it was investigating unauthorized access. Hacker group TeamPCP claimed responsibility and attempted to sell the stolen data online. GitHub has removed the malicious packages and is continuing to determine the scope of the incident. It has not disclosed any transaction amount or asking price for the data.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.