AI Security #GitHub#supply chain#VS Code#security breach#TeamPCP#npm

GitHub Confirms 3,800 Internal Repos Stolen via Poisoned VS Code Extension

Threat actor group TeamPCP exfiltrated thousands of GitHub internal repositories through a trojanized Nx Console VS Code extension that was live on the marketplace for just 18 minutes.

Wednesday May 20, 2026
GitHub Confirms 3,800 Internal Repos Stolen via Poisoned VS Code Extension

Summary

Threat actor group TeamPCP exfiltrated thousands of GitHub internal repositories through a trojanized Nx Console VS Code extension that was live on the marketplace for just 18 minutes.

Key Takeaways

Frequently Asked Questions

Q: What is this story about? A: Threat actor group TeamPCP exfiltrated thousands of GitHub internal repositories through a trojanized Nx Console VS Code extension that was live on the marketplace for just 18 minutes…

Back to all news