GitHub Confirms Breach of 3,800 Internal Repositories via Poisoned VS Code Extension

A poisoned Nx Console VS Code extension gave a threat actor access to roughly 3,800 of GitHub's internal repositories. The trojanized build was live on the VS Code Marketplace for 18 minutes.

GitHub Confirms Breach of 3,800 Internal Repositories via Poisoned VS Code Extension

A poisoned build of the Nx Console VS Code extension gave a threat actor access to roughly 3,800 of GitHub's internal repositories. GitHub detected the compromise on May 19 and confirmed the breach publicly on May 20 after finding the compromised extension on an employee's device.

The trojanized extension, published under the legitimate package ID nrwl.angular-console, was live on the Visual Studio Marketplace for 18 minutes on May 18 — from 12:30 p.m. to 12:48 p.m. UTC. That window was enough. The extension looked and behaved like the real Nx Console, but on startup it silently executed a shell command that downloaded and executed a hidden package disguised as routine setup activity.

The payload was a credential stealer. It harvested tokens and secrets from 1Password vaults, Anthropic Claude Code configurations, npm, GitHub, and AWS. The compromise originated from the broader TanStack supply-chain attack, which also hit OpenAI, Mistral AI, and Grafana Labs.

A group calling itself TeamPCP claimed responsibility. On the Breached cybercrime forum, TeamPCP posted that it had access to roughly 4,000 private repositories and was seeking a minimum of $50,000 for the data. GitHub's own count — approximately 3,800 repos — roughly matches that figure.

GitHub says there is no evidence of customer data exposure. The exfiltration appears limited to internal repositories — source code, not customer enterprises, organizations, or stored data. The company removed the malicious extension version, isolated the affected endpoint, and initiated incident response immediately.

VS Code extensions run with the same permissions as the developer using them. There is no sandbox. A poisoned extension on an engineer's machine has access to everything that engineer has access to — tokens, credentials, local files, connected services. Microsoft's Visual Studio Marketplace has faced repeated incidents: in 2024, researchers at Aqua Security identified extensions with cryptominers that had accumulated over 6.2 million installs before removal. The marketplace's review process still does not enforce code signing or runtime isolation for published extensions.

TeamPCP has prior form. The group has been linked to supply-chain attacks targeting GitHub, PyPI, npm, and Docker, and was previously connected to the "Mini Shai-Hulud" campaign that targeted OpenAI employees.

Source: BleepingComputer, The Hacker News

Comments

Get tomorrow's roundup. Free.

One email each morning. Sneakers, sports, culture, tech.

Link copied