GitHub confirms breach — thousands of internal repositories hit after employee installs malicious VS Code extension
GitHub has confirmed a cyberattack that resulted in the theft of sensitive internal repositories. The breach occurred when an employee's device was compromised through a malicious VSCode extension. The attackers, known as TeamPCP, are reportedly selling an archive of around 4,000 repositories on the dark web.
- ▪GitHub confirmed that an employee's device was compromised due to a poisoned VSCode extension.
- ▪The attackers, TeamPCP, are offering an archive of approximately 4,000 repositories for sale on the dark web for $50,000.
- ▪GitHub has taken steps to mitigate the breach by rotating critical secrets and monitoring for further activity.
2 outlets in our directory ran this story, first to last over 28 hours. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
TechRadar publishes from United Kingdom and files mainly under tech. We currently carry 1,522 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | TechRadar |
| Canonical URL | https://www.techradar.com/pro/security/github-confirms-breach-thousands-of-internal-repositories-hit-after-employee-installs-malicious-vs-code-extension |
| Publication time | Thu, 21 May 2026 13:20:00 +0000 |
| Retrieval time | 2026-05-21T13:26:11.040Z |
| Last seen | 2026-05-21T13:26:11.040Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | Id-AVZTyeRlY · 2 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Pro Security GitHub confirms breach — thousands of internal repositories hit after employee installs malicious VS Code extension News By Sead Fadilpašić published 21 May 2026 TeamPCP continues its attack on open source projects When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. (Image credit: Gil C / Shutterstock) Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter GitHub confirms an employee’s compromised device led to exfiltration of internal repositories via a poisoned VSCode extensionThreat actors TeamPCP are selling an archive of roughly 4,000 repos on the dark web, asking $50,000 with…
Excerpt limited to ~120 words for fair-use compliance. The full article is at TechRadar.