GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
Security researchers say 5,500 GitHub repositories have been affected by the attack.
TeamPCP continues its attack on open source projects, now apparently asking for $50,000.
GitHub confirms breach of 3,800 internal repos after employee installs poisoned VS Code extension - SiliconANGLE ...
The code hosting giant GitHub said it was investigating a breach but said there was no evidence of customer data theft.
GitHub CISO Alexis Wales confirmed Thursday that a poisoned build of the Nx Console Visual Studio Code extension — live on ...
A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual ...
Sometime in early 2025, an attacker slipped malicious code into a Visual Studio Code extension, and a GitHub employee ...
The Microsoft-owed software developer platform, GitHub, has confirmed a third-party has gained unauthorized access to 3800 ...
GitHub confirmed an attacker was able to access its internal repositories after a code extension breach, with TeamPCP ...
Free and open source Codeium has launched an assault on the front-running, for-pay GitHub Copilot tool in the coding assistant space. Along with being free of OpenAI hegemony, a key selling point in ...