GitHub says hackers stole data from thousands of internal repositories
AI-summarised brief · reviewed before publication
GitHub confirmed a hack resulting in the theft of data from approximately 3,800 internal code repositories. The breach occurred through a compromised employee device involving a poisoned VS Code extension. GitHub stated it has no evidence of impact to customer information stored outside its internal repositories, but the investigation is ongoing. Hackers, including a group called TeamPCP, are increasingly targeting open-source projects to compromise developers' computers. TeamPCP has taken credit for the GitHub breach and is selling the stolen data on a cybercrime forum, having previously breached the European Commission and other targets. GitHub's internal repositories were affected, with the company still investigating.
💡 Why It Matters
- · The breach highlights the vulnerability of popular coding extensions to targeted attacks.
- · TeamPCP's ability to sell stolen data on cybercrime forums amplifies the potential damage.