TGViewer
Doprax Doprax @dopraxcloud · 2.49K subscribers
Post #47 3.55K
GitHub breach. Same crew as last week's npm worm.

GitHub confirmed unauthorized access to its internal repositories. A poisoned VS Code extension on an employee device, ~3,800 internal repos exfiltrated. No evidence yet of impact to customer enterprises, organizations, or repos.

Attribution: TeamPCP. The same group behind the Mini Shai-Hulud npm worm that hit TanStack, UiPath, Mistral AI, and 165+ other packages on May 11.

If you run code on a Doprax VM and use GitHub:
→ Rotate GitHub PATs, OAuth tokens, Actions secrets
→ Audit VS Code extensions installed on your dev machines
→ Review recent repo activity for anything you didn't push

GitHub rotated its critical secrets overnight. Downstream systems should follow.
Two TeamPCP attacks in nine days, both targeting developer tooling. The pattern is clear: registries, extensions, CI runners. Treat each install like the privileged operation it is.
More from @dopraxcloud
  1. Sep 30, 2026⚠️ OVH VM prices change on October 1 OVH has changed its prices several times this year. W…
  2. Sep 28, 2026IPv4 addresses are limited, so providers reuse them. If a past owner sent spam, attacked o…
  3. Sep 24, 2026Not sure which port to run your service on? Quick answer, with the reasons: → Use 443 (HTT…
  4. Sep 22, 2026When the network is unstable, your service or app will sometimes be offline or unavailable…
  5. Sep 17, 2026As we mentioned previously, ProVM now supports up to 5 additional IPs per VM, which means…
  6. Sep 12, 2026We’ve reactivated the “pay by card” payment method! You can now pay with credit card, Goog…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →