GitHub Internal Breach: TeamPCP Exfiltrates 3,800 Repos via Poisoned VS Code Extension

Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.

GitHub Internal Breach: TeamPCP Exfiltrates 3,800 Repos via Poisoned VS Code Extension
📌
Security Roundup Series: Week of May 21, 2026 • 4 min read deep dive

On May 20, 2026, GitHub confirmed that approximately 3,800 of its internal repositories were exfiltrated by the threat group TeamPCP — traceable to a poisoned version of the Nx Console Visual Studio Code extension that was live on the VS Code Marketplace for just 18 minutes.


Background: TeamPCP and the TanStack Campaign

TeamPCP (also tracked as UNC6780) is a financially and intelligence-motivated threat group specializing in software supply chain attacks. Their signature technique is the "Mini Shai-Hulud" worm: a self-replicating payload that steals CI/CD credentials and automatically publishes infected versions of dependent packages. The week prior, TeamPCP had compromised 42 TanStack packages, 65 UiPath packages, Mistral AI's PyPI packages, the OpenSearch JavaScript client, Guardrails AI, and others — publishing 401 malicious package artifacts within 5 hours (CVE-2026-45321, CVSS 9.6).


Attack Chain: How GitHub Was Breached

  1. TanStack npm compromise: TeamPCP poisoned @tanstack/react-query and related packages with credential-harvesting payloads stealing npm, AWS, GitHub, and GCP tokens from developer CI/CD environments.
  2. Nx Console VS Code extension backdoored: Using stolen GitHub credentials, TeamPCP pushed a malicious commit to the official nrwl/nx repository. The trojanized Nx Console appeared on the Marketplace between 12:30–12:48 PM UTC on May 18, 2026 — 18 minutes.
  3. GitHub employee installs extension: A GitHub engineer installed the extension during that window. It appeared visually identical to the legitimate version but executed a hidden shell command on startup, downloading a credential-stealing payload.
  4. Credential exfiltration: The stealer harvested GitHub personal access tokens and session cookies, AWS IAM credentials, 1Password vault contents, Anthropic Claude Code API configurations, and npm publish tokens.
  5. Mass repository cloning: With the stolen GitHub token, TeamPCP scripted a clone of approximately 3,800 internal repositories before detection triggered a response.

What Was Stolen

TeamPCP posted the stolen repositories for sale at a minimum of $50,000 USD. Exfiltrated material includes GitHub Actions workflow definitions, Copilot internal model fine-tuning scripts and evaluation harnesses, CodeQL rules and internal security tooling, Codespaces and Dependabot implementations, and Rails/PR controller source code. GitHub's assessment: no customer data, production secrets, or cryptographic key material was confirmed exfiltrated. Grafana Labs disclosed a secondary breach via the same vector.


What to Do

Audit VS Code extensions immediately:

code --list-extensions --show-versions

Rotate all developer credentials if Nx Console was installed between May 16–19: GitHub personal access tokens and SSH keys, npm publish tokens, AWS IAM access keys, and all secrets stored in 1Password or similar vaults.

Review CI/CD pipeline outputs: Check GitHub Actions logs for unexpected curl/wget calls or unauthorized pushes around May 14–19.

Enforce VS Code extension allowlisting: Use extensions.allowedExtensionIDs in enterprise deployments or a third-party extension governance tool.

Enable fine-grained PATs: Use fine-grained personal access tokens with minimum required scopes and enforce this via organization policy.

→ Back to the Week of May 21 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther