📰 Full Story
A prolific cybercrime group calling itself TeamPCP has exfiltrated roughly 3,800–4,000 internal GitHub repositories after a compromised developer device installed a poisoned Visual Studio Code extension, GitHub said.
The malicious Nx Console v18.95.0 build was available on Microsoft’s Visual Studio Marketplace for about 18 minutes on May 18 before being removed; GitHub confirmed the intrusion publicly on May 20 and continues investigating.
Researchers say the incident is the latest phase of an automated, self‑propagating campaign — driven by a worm called Mini Shai‑Hulud — that has staged at least 20 waves and poisoned more than 500 packages across npm, PyPI and other ecosystems.
The campaign uses credential‑stealing payloads in developer tools to harvest long‑lived CI/CD tokens, then publishes tainted packages that compromise further projects; victims cited in reporting include OpenAI and others.
TeamPCP offered the stolen GitHub repositories for sale on cybercrime forums (reports indicate an asking price of at least $50,000). GitHub says its current assessment is the compromise was limited to internal repositories and that it has rotated critical secrets and isolated the affected endpoint.
🔗 Based On
🕰️ The Story So Far: An Evolving Timeline
Sunday, May 24, 2026 01:08 UTC
TeamPCP Worm Breaches Thousands of GitHub Repositories
Friday, May 22, 2026 10:35 UTC
Poisoned VS Code Extension Breaches GitHub
Wednesday, May 20, 2026 15:45 UTC
GitHub breach exposes around 3,800 internal repositories







💬 Commentary