• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Hacking Group TeamPCP Steals 3,800 GitHub Repositories Via Poisoned VS Code Extension

  • SOFX Staff Writer
  • May 21, 2026
(Bangla press / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

GitHub confirmed on May 20 that approximately 3,800 internal code repositories were exfiltrated after an employee installed a poisoned Visual Studio Code (VS Code) extension, the latest intrusion attributed to TeamPCP, a hacking group formally tracked by Google Threat Intelligence Group (GTIG) as UNC6780.

GitHub stated in posts on X that it detected and contained the compromise, removed the malicious extension version, isolated the affected endpoint, and rotated critical credentials, prioritizing the highest-impact secrets first.

“We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity,” the company said. GitHub added it had no evidence that customer data stored outside of its internal repositories was impacted and said it would publish a full report when the investigation concludes.

TeamPCP advertised the allegedly stolen data on the Breached cybercrime forum for at least $50,000 and stated the listing was not a ransom demand. GitHub confirmed TeamPCP’s reported figure of approximately 3,800 affected repositories was “directionally consistent” with its investigation.

The extension involved in the breach is believed to be Nx Console version 18.95.0, a VS Code tool with more than 2.2 million installs used to manage JavaScript development workflows.

NX Chief Executive Officer Jeff Cross said on X that while Microsoft initially indicated 28 installs of the malicious version, NX’s own analytics place the number of potentially affected users above 6,000.

Aikido Security researcher Mackenzie Jackson said TeamPCP has compromised Trivy, Checkmarx, Bitwarden CLI, TanStack, and GitHub within 2026, all through developer tooling. “A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories,” Jackson said. “Most security teams still have zero visibility into what extensions or packages are on their developers’ machines. That’s the blind spot these attacks keep walking through.”

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

IED Found Underwater at Alabama Dam Supplying Drinking Water to 350,000 People

IED Found Underwater at Alabama Dam Supplying Drinking Water to 350,000 People

by SOFX Staff Writer
May 15, 2026
4

An improvised explosive device (IED) described as grenade-type was discovered underwater at a drinking water reservoir in Alabama this week...

AI Data Center Demand Drove 76 Percent Surge in Wholesale Power Prices Across East Cost Grid

AI Data Center Demand Drove 76 Percent Surge in Wholesale Power Prices Across East Cost Grid

by SOFX Staff Writer
May 15, 2026
1

Wholesale electricity prices across America's largest power grid jumped 76 percent in the first quarter of 2026, driven by surging...

Iran Seizes Chinese-Operated ‘Floating Armory’ Near Strait of Hormuz, Says Reports

Iran Seizes Chinese-Operated ‘Floating Armory’ Near Strait of Hormuz, Says Reports

by SOFX Staff Writer
May 15, 2026
3

A vessel operating as a floating armory was seized by unauthorized personnel near the Strait of Hormuz on Thursday and...

Air Force Tests Special Ops Plane Designed for Rapid Assembly in the Field

Air Force Tests Special Ops Plane Designed for Rapid Assembly in the Field

by SOFX Staff Writer
May 20, 2026
1

The U.S. Air Force Special Operations Command (AFSOC) is testing whether its new OA-1K Skyraider II aircraft can be rapidly...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Defense Contractors Named in EPIC Audit of 38 Firms Blocking Consumer Data Opt-Outs

Defense Contractors Named in EPIC Audit of 38 Firms Blocking Consumer Data Opt-Outs

Pentagon Taps Shield AI to Power LUCAS Drone Swarms With Hivemind Software

Pentagon Taps Shield AI to Power LUCAS Drone Swarms With Hivemind Software

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz