GitHub Confirms 3,800 Internal Repos Stolen via Poisoned VS Code Extension

Threat actor group TeamPCP exfiltrated thousands of GitHub internal repositories through a trojanized Nx Console VS Code extension that lived on the marketplace for just 18 minutes.

Wednesday May 20, 2026 Source: thehackernews.com
TL;DR — Quick Answer

GitHub has confirmed that threat actor group TeamPCP stole roughly 3,800 internal repositories by trojanizing the Nx Console VS Code extension, which was live on the marketplace for only 18 minutes before removal. The poisoned extension abused trusted marketplace publishing credentials to reach victim machines, harvesting source code from affected organizations. GitHub says public repositories were unaffected and is notifying impacted customers, while urging developers to audit extensions and rotate exposed tokens.

Key Takeaways

GitHub Confirms 3,800 Internal Repos Stolen via Poisoned VS Code Extension — AI news article illustration

GitHub has confirmed a supply-chain breach in which threat actor group TeamPCP exfiltrated thousands of internal repositories through a trojanized copy of the Nx Console VS Code extension — one that was live on the official marketplace for just 18 minutes.

How the Attack Worked

The vector was trust itself. VS Code extensions run with the developer’s privileges on the local machine, and a marketplace listing carries an implicit vetting signal. The trojanized Nx Console extension — published in the brief window before detection — executed malicious code on developer machines, which then reached into accessible internal repositories and exfiltrated source code back to the attackers. The speed is the story: 18 minutes of marketplace exposure was enough to harvest roughly 3,800 internal repositories from affected organizations.

Scope and Response

Why Extensions Are the Perfect Trojan

Developer tooling has become a prime supply-chain target because it combines three things attackers love: trusted distribution channels, execution on valuable machines, and access to source code and secrets. The wave of 2026 npm and VS Code marketplace incidents — typosquatting packages, hijacked publisher accounts, and now a poisoned extension — points to the same lesson: the marketplace badge is not a security boundary.

What This Means

For security teams, the takeaway is that extension ecosystems need the same treatment as any third-party dependency: inventory what is installed, verify publishers, pin versions where possible, and scope what a compromised developer workstation can actually reach. Eighteen minutes is a very short window — and a very large blast radius.

Frequently Asked Questions

How did attackers steal 3,800 GitHub repositories?

Threat actor group TeamPCP trojanized the Nx Console VS Code extension and published it to the official marketplace, where it executed malicious code on developer machines that exfiltrated internal repositories from affected organizations.

How long was the poisoned Nx Console extension on the marketplace?

Only 18 minutes — the extension was live briefly before being detected and removed, but that window was enough to compromise developer environments and steal thousands of repositories.

Were public GitHub repositories affected by the breach?

No. GitHub states that public repositories were unaffected; the theft targeted internal, private repositories at organizations where infected developer machines had access.

How can developers protect against trojanized VS Code extensions?

Audit installed extensions for unexpected updates or publisher changes, remove untrusted ones, rotate any tokens or credentials exposed on affected machines, and treat marketplace-published extensions as code running with full developer privileges.

This article is based on the official announcement from thehackernews.com . Read the original for full technical details.

Related Articles

Back to all news