<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GitHub Is Investigating Unauthorized Access to Internal Repositories After Employee Device Compromise]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1779259808870-90518095-78ff-4861-b7b7-58e74e9725f6-image.png" alt="90518095-78ff-4861-b7b7-58e74e9725f6-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">GitHub confirmed on Wednesday that it is investigating unauthorized access to its internal repositories following the compromise of an employee device. The developer platform said it detected the breach on Tuesday, identifying a poisoned VS Code extension as the vector through which the employee's device was compromised. GitHub said it removed the malicious extension version, isolated the affected endpoint, and began incident response immediately. The company stated it currently has no evidence of impact to customer information stored outside its internal repositories but said it is closely monitoring its infrastructure for any follow-on activity as the investigation continues.</p>
<p dir="auto">A hacking group called TeamPCP has reportedly claimed responsibility for the compromise and has attempted to sell the stolen data on underground forums, claiming to possess approximately 4,000 private code repositories related to GitHub's main platform and internal organizations. SecurityWeek describes TeamPCP as a sophisticated, automation-heavy group that specializes in turning compromised developer tools into credential-harvesting machines for financial gain, a profile consistent with the VS Code extension attack vector used in this incident. Binance founder Changpeng Zhao responded to the news by advising developers to immediately review and rotate any API keys stored in their code, including in private repositories, noting the window of potential exposure created by the breach. GitHub has not confirmed or denied the scope of data TeamPCP claims to have obtained.</p>
]]></description><link>https://undeads.com/forum/topic/20254/github-is-investigating-unauthorized-access-to-internal-repositories-after-employee-device-compromise</link><generator>RSS for Node</generator><lastBuildDate>Fri, 19 Jun 2026 17:34:25 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/20254.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 06:50:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to GitHub Is Investigating Unauthorized Access to Internal Repositories After Employee Device Compromise on Wed, 20 May 2026 09:03:24 GMT]]></title><description><![CDATA[<p dir="auto">CZ said rotate your API keys immediately, solid advice regardless of scope</p>
]]></description><link>https://undeads.com/forum/post/56767</link><guid isPermaLink="true">https://undeads.com/forum/post/56767</guid><dc:creator><![CDATA[tradelikepro]]></dc:creator><pubDate>Wed, 20 May 2026 09:03:24 GMT</pubDate></item></channel></rss>