GitHub breach. Same crew as last week's npm worm.
GitHub confirmed unauthorized access to its internal repositories. A poisoned VS Code extension on an employee device, ~3,800 internal repos exfiltrated. No evidence yet of impact to customer enterprises, organizations, or repos.
Attribution: TeamPCP. The same group behind the Mini Shai-Hulud npm worm that hit TanStack, UiPath, Mistral AI, and 165+ other packages on May 11.
If you run code on a Doprax VM and use GitHub:
→ Rotate GitHub PATs, OAuth tokens, Actions secrets
→ Audit VS Code extensions installed on your dev machines
→ Review recent repo activity for anything you didn't push
GitHub rotated its critical secrets overnight. Downstream systems should follow.
Two TeamPCP attacks in nine days, both targeting developer tooling. The pattern is clear: registries, extensions, CI runners. Treat each install like the privileged operation it is.
Post #47
3.55K
