‹ Back to Home

GitHub Leak: 3,800 Internal Repos Compromised via Malicious VS Code Extension

GitHub says a rogue VS Code extension used by an employee exposed nearly 4,000 private repos. A shadowy group called TeamPCP claims they’re behind it.

Keerthika 5 min read 284
Follow on Google
Updated 4 months ago
Security GitHub Leak: 3,800 Internal Repos Compromised via Malicious VS Code Extension 5 min left Follow on Google
GitHub Leak: 3,800 Internal Repos Compromised via Malicious VS Code Extension

TamilTech AI summary

GitHub confirmed that roughly 3,800 internal repositories were read by an attacker after an employee installed a malicious VS Code extension from the official Marketplace that quietly stole the user’s GitHub OAuth token and cloned private repos. The breach was caught in a routine audit; the token only allowed read access so no code was changed, yet the exfiltration of internal source still matters because it exposes proprietary logic, configs, and early product ideas. A group calling itself TeamPCP claimed credit and described the extension as a spear-phishing tool aimed at high-value dev environments, matching the timeline. For everyday developers the public cloud side is unaffected, but the incident highlights supply-chain risk from extensions, the danger of long-lived tokens on local machines, and the need to rotate PATs, enable 2FA, prefer SSH keys, revoke unknown OAuth apps, and uninstall anything you don’t recognize. GitHub has already pulled the extension, revoked the token, begun sweeping similar add-ons, and announced a stricter Extension Trust Program, so treat every third-party tool as a potential risk and watch the GitHub Blog for further hardening steps.

  • GitHub says ~3,800 internal repos were accessed after a rogue VS Code extension stole an employee’s OAuth token.
  • Hacking group TeamPCP claimed responsibility, highlighting supply‑chain risks for developers.
  • Indian devs should rotate tokens, enable 2FA, and audit extensions to avoid similar attacks.

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

What happened?

GitHub has confirmed that about 3,800 internal repositories were accessed by an unauthorised party after an employee installed a malicious Visual Studio Code extension. The extension, posted on the official VS Code Marketplace, turned out to be a trojan that harvested the employee’s authentication token and used it to clone private repos.

The breach was discovered during a routine security audit. GitHub says the attacker only had read‑only access and did not alter any code, but the fact that source code from internal projects was exfiltrated is a big deal for a platform that hosts millions of open‑source projects worldwide.

Who’s taking credit?

A hacking collective that calls itself TeamPCP posted a claim of responsibility on a public forum, saying they targeted “high‑value development environments” and that the VS Code extension was a “spear‑phishing” tool. They didn’t release any data, but the claim matches the timeline of the GitHub audit.

How the extension worked

The rogue VS Code add‑on was disguised as a productivity tool for JavaScript developers. When a user installed it, the extension silently requested the GitHub OAuth token stored in the VS Code credential manager. Once it had the token, it called the GitHub API to list all repositories the user could access and then cloned them to a remote server controlled by the attackers.

Because the token was scoped for the employee’s internal account, the API calls were treated as legitimate, and GitHub’s security systems didn’t flag the activity as suspicious until the audit team noticed a spike in outbound traffic.

Impact on developers

For most developers using GitHub’s public cloud, the breach doesn’t affect them directly. However, the incident raises a few red flags:

  • Supply‑chain risk: Even trusted extensions can become attack vectors.
  • Credential hygiene: Storing long‑lived OAuth tokens on local machines is risky.
  • Internal code exposure: Private repos often contain proprietary algorithms, security configs, or early‑stage product ideas that competitors could exploit.

What Indian developers should do

India’s dev community heavily relies on GitHub for open‑source contributions and for private enterprise projects. Here’s a quick checklist to tighten your security posture:

  1. Open VS Code, go to Extensions view and uninstall any extension you don’t recognise.
  2. Rotate your GitHub personal access tokens (PATs) every 90 days. Use the Fine‑grained PAT option to limit scope.
  3. Enable Two‑Factor Authentication (இரண்டு-நிலை பாதுகாப்பு) on your GitHub account.
  4. Prefer SSH keys over HTTPS tokens for repo access.
  5. Review the OAuth Apps page in GitHub settings and revoke any suspicious apps.

GitHub’s response

GitHub has taken the following steps:

  • Removed the malicious extension from the Marketplace.
  • Revoked the compromised OAuth token and forced a password reset for the employee.
  • Started a broader sweep of all extensions that request GitHub scopes.
  • Announced a new “Extension Trust Program” that will require additional vetting for any add‑on that accesses source‑control APIs.

The company also promised to notify any affected enterprise customers directly, though it has not disclosed which organisations were involved.

Our take – TamilTech’s opinion

From a security standpoint, this is a classic supply‑chain attack that shows how a single developer’s mistake can jeopardise an entire ecosystem. The fact that the attacker only needed a single employee’s token to scrape thousands of repos is a wake‑up call for all of us.

In India, many startups still use shared GitHub accounts and long‑lived tokens for CI pipelines. Those practices make it easier for a rogue extension to gain a foothold. We recommend moving to organization‑level permissions, using GitHub Actions with short‑lived OIDC tokens, and regularly auditing token usage.

TeamPCP’s claim, while not yet verified, is a reminder that hacktivist groups are actively looking for low‑hanging fruit in the developer supply chain. The next target could be a popular NPM package or a Docker image.

What’s next?

GitHub will likely tighten its extension review process and push for more granular token scopes. Developers should keep an eye on the GitHub Blog for updates.

In the meantime, treat every third‑party tool as a potential risk. If something sounds too good to be true, it probably is – especially when it asks for access to your code.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications