Skip to content
AI IntelligenceMay 20, 2026AI Intelligence
Article

GitHub confirmed that a poisoned VS Code extension on an employee's device gave attackers access to roughly 3,800 internal repositories.

The threat group TeamPCP is already advertising the stolen data — an alarming incident for software supply chain security.

AI-generated: summaries written by AI from the linked sources. How we use AI

AI-generatedSource: VentureBeat
01

Source Brief

GitHub confirmed that a poisoned VS Code extension on an employee's device gave attackers access to roughly 3,800 internal repositories. The threat group TeamPCP is already advertising the stolen data — an alarming incident for software supply chain security.