• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Hacking Group TeamPCP Steals 3,800 GitHub Repositories Via Poisoned VS Code Extension

  • SOFX Staff Writer
  • May 21, 2026
(Bangla press / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

GitHub confirmed on May 20 that approximately 3,800 internal code repositories were exfiltrated after an employee installed a poisoned Visual Studio Code (VS Code) extension, the latest intrusion attributed to TeamPCP, a hacking group formally tracked by Google Threat Intelligence Group (GTIG) as UNC6780.

GitHub stated in posts on X that it detected and contained the compromise, removed the malicious extension version, isolated the affected endpoint, and rotated critical credentials, prioritizing the highest-impact secrets first.

“We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity,” the company said. GitHub added it had no evidence that customer data stored outside of its internal repositories was impacted and said it would publish a full report when the investigation concludes.

TeamPCP advertised the allegedly stolen data on the Breached cybercrime forum for at least $50,000 and stated the listing was not a ransom demand. GitHub confirmed TeamPCP’s reported figure of approximately 3,800 affected repositories was “directionally consistent” with its investigation.

The extension involved in the breach is believed to be Nx Console version 18.95.0, a VS Code tool with more than 2.2 million installs used to manage JavaScript development workflows.

NX Chief Executive Officer Jeff Cross said on X that while Microsoft initially indicated 28 installs of the malicious version, NX’s own analytics place the number of potentially affected users above 6,000.

Aikido Security researcher Mackenzie Jackson said TeamPCP has compromised Trivy, Checkmarx, Bitwarden CLI, TanStack, and GitHub within 2026, all through developer tooling. “A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories,” Jackson said. “Most security teams still have zero visibility into what extensions or packages are on their developers’ machines. That’s the blind spot these attacks keep walking through.”

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Navy Drone Boat Pulls Off First Rescue of a Downed US Apache Crew

Navy Drone Boat Pulls Off First Rescue of a Downed US Apache Crew

by SOFX Staff Writer
June 10, 2026
0

A U.S. Navy drone boat rescued the crew of a U.S. Army Apache helicopter that went down in the Gulf...

Majority of Planned U.S. AI Data Centers to Be Built in Drought-Stricken Areas, Analysis Finds

Majority of Planned U.S. AI Data Centers to Be Built in Drought-Stricken Areas, Analysis Finds

by SOFX Staff Writer
June 11, 2026
2

Most of the new artificial intelligence (AI) data centers planned across the United States (U.S.) are set to be built...

Former Navy Sailor Among Three Arrested for Supporting ISIS Plot to Attack U.S. Troops

Former Navy Sailor Among Three Arrested for Supporting ISIS Plot to Attack U.S. Troops

by SOFX Staff Writer
June 9, 2026
2

The FBI arrested three men Friday, including a former U.S. Navy sailor, for allegedly conspiring to support ISIS, including providing...

Ukraine Develops AI-Powered Interceptor Drone That Autonomously Downs Shaheds

Ukraine Develops AI-Powered Interceptor Drone That Autonomously Downs Shaheds

by SOFX Staff Writer
June 9, 2026
1

Ukraine has developed interceptor drones that can autonomously identify and shoot down Russian Shahed attack drones. Ukrainian Defense Minister Mykhailo...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Defense Contractors Named in EPIC Audit of 38 Firms Blocking Consumer Data Opt-Outs

Defense Contractors Named in EPIC Audit of 38 Firms Blocking Consumer Data Opt-Outs

Pentagon Taps Shield AI to Power LUCAS Drone Swarms With Hivemind Software

Pentagon Taps Shield AI to Power LUCAS Drone Swarms With Hivemind Software

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz