GitHub Internal Breach: TeamPCP Exfiltrates 3,800 Repos via Poisoned VS Code Extension
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
On May 20, 2026, GitHub confirmed that approximately 3,800 of its internal repositories were exfiltrated by the threat group TeamPCP — traceable to a poisoned version of the Nx Console Visual Studio Code extension that was live on the VS Code Marketplace for just 18 minutes.
Background: TeamPCP and the TanStack Campaign
TeamPCP (also tracked as UNC6780) is a financially and intelligence-motivated threat group specializing in software supply chain attacks. Their signature technique is the "Mini Shai-Hulud" worm: a self-replicating payload that steals CI/CD credentials and automatically publishes infected versions of dependent packages. The week prior, TeamPCP had compromised 42 TanStack packages, 65 UiPath packages, Mistral AI's PyPI packages, the OpenSearch JavaScript client, Guardrails AI, and others — publishing 401 malicious package artifacts within 5 hours (CVE-2026-45321, CVSS 9.6).
Attack Chain: How GitHub Was Breached
- TanStack npm compromise: TeamPCP poisoned
@tanstack/react-queryand related packages with credential-harvesting payloads stealing npm, AWS, GitHub, and GCP tokens from developer CI/CD environments. - Nx Console VS Code extension backdoored: Using stolen GitHub credentials, TeamPCP pushed a malicious commit to the official
nrwl/nxrepository. The trojanized Nx Console appeared on the Marketplace between 12:30–12:48 PM UTC on May 18, 2026 — 18 minutes. - GitHub employee installs extension: A GitHub engineer installed the extension during that window. It appeared visually identical to the legitimate version but executed a hidden shell command on startup, downloading a credential-stealing payload.
- Credential exfiltration: The stealer harvested GitHub personal access tokens and session cookies, AWS IAM credentials, 1Password vault contents, Anthropic Claude Code API configurations, and npm publish tokens.
- Mass repository cloning: With the stolen GitHub token, TeamPCP scripted a clone of approximately 3,800 internal repositories before detection triggered a response.
What Was Stolen
TeamPCP posted the stolen repositories for sale at a minimum of $50,000 USD. Exfiltrated material includes GitHub Actions workflow definitions, Copilot internal model fine-tuning scripts and evaluation harnesses, CodeQL rules and internal security tooling, Codespaces and Dependabot implementations, and Rails/PR controller source code. GitHub's assessment: no customer data, production secrets, or cryptographic key material was confirmed exfiltrated. Grafana Labs disclosed a secondary breach via the same vector.
What to Do
Audit VS Code extensions immediately:
code --list-extensions --show-versionsRotate all developer credentials if Nx Console was installed between May 16–19: GitHub personal access tokens and SSH keys, npm publish tokens, AWS IAM access keys, and all secrets stored in 1Password or similar vaults.
Review CI/CD pipeline outputs: Check GitHub Actions logs for unexpected curl/wget calls or unauthorized pushes around May 14–19.
Enforce VS Code extension allowlisting: Use extensions.allowedExtensionIDs in enterprise deployments or a third-party extension governance tool.
Enable fine-grained PATs: Use fine-grained personal access tokens with minimum required scopes and enforce this via organization policy.
→ Back to the Week of May 21 Security Roundup