GitHub Internal Repositories Breached via Malicious Extension | MSSP Advisory

CriticalCredible Report
DateMay 20, 2026
📋Executive Summary
GitHub confirmed attackers exfiltrated code from approximately 3,800 internal repositories through a compromised employee device infected with a malicious Visual Studio Code extension. The TeamPCP threat group claims responsibility and is attempting to sell the stolen source code for at least $50,000.
⚠️Why It Matters for MSSPs
Your own development team likely uses VS Code extensions daily, making your internal repositories and client code equally vulnerable to the same supply chain attack vector. Every client you advise about secure development practices now needs immediate guidance on extension vetting since GitHub itself fell victim to this attack method.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Supply Chain

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.