HyperAIHyperAI

Command Palette

Search for a command to run...

2 months ago
Security

Hackers steal data from thousands of GitHub internal repos

GitHub, the Microsoft-owned developer platform, confirmed a security breach affecting approximately 3,800 internal code repositories. The company announced the incident via X, stating it had detected and contained a compromise involving an employee device infected by a poisoned Visual Studio Code extension. This plugin, widely used for programming, served as the entry point for the attackers to access internal data. Despite the intrusion, GitHub emphasized there is currently no evidence that customer information stored outside of its internal repositories was impacted. The company noted that its investigation remains ongoing and did not specify which particular extension was compromised. The breach highlights a growing trend where hackers target popular open-source projects and coding tools to distribute malware to large numbers of developers simultaneously. A hacking group known as TeamPCP has claimed responsibility for the attack and is reportedly selling the stolen data on a cybercrime forum. TeamPCP is a recurring threat actor previously linked to a significant breach of the European Commission, where they stole over 90 gigabytes of data. That incident involved compromising Trivy, a vulnerability scanning tool, to push info-stealing malware to its users and subsequently steal cloud keys. This GitHub incident mirrors a separate attack on OpenAI, where hackers infiltrated the Tanstack platform to inject malicious updates designed to steal user passwords and access tokens. When contacted for further details, GitHub did not immediately respond to questions regarding whether the attackers had made ransom demands or contacted the company directly. While the breach poses a risk to internal code and infrastructure, the company maintains that external customer data remains secure. The incident underscores the vulnerabilities inherent in the software supply chain and the sophisticated methods attackers use to compromise development environments through trusted tools.

Related Links