- GitHub confirms a breach of its internal repositories via a poisoned Visual Studio Code extension.
- The attack was part of the larger TanStack supply chain campaign, impacting OpenAI, Mistral AI, and Grafana Labs.
- The malicious extension was live for only 18 minutes but stole credentials for 1Password, GitHub, AWS, and more.
On May 21, 2026, GitHub officially confirmed a major breach of its internal repositories, an incident resulting from a compromised employee device infected by a malicious version of the Nx Console extension for Microsoft Visual Studio Code. The attack, attributed to the cybercriminal group TeamPCP, allowed the exfiltration of approximately 3,800 repositories and was linked to the broader TanStack supply chain attack that also hit companies like OpenAI, Mistral AI, and Grafana Labs.
According to the company’s Chief Information Security Officer, Alexis Wales, the breach involved internal repositories containing some customer information, such as excerpts of support interactions. Consequently, GitHub has rotated critical secrets and taken containment steps while monitoring for further activity. Meanwhile, the trojanized extension was available on the Visual Studio Marketplace for merely 18 minutes, yet it executed a credential stealer targeting 1Password vaults, Anthropic Claude Code configurations, npm, GitHub, and Amazon Web Services.
The incident underscores critical vulnerabilities in developer tooling security. Jeff Cross, co-founder of Narwhal Technologies, stated on X that it highlights the need for “deeper, more fundamental changes” in securing open-source distribution. However, as noted by OX Security researcher Nir Zadok, the extension appeared normal but secretly ran a shell command downloading malicious code from a planted commit on the official nrwl/nx GitHub repository. This pattern enables a self-sustaining cycle of compromises, as described by Aikido security researcher Raphael Silva, where auto-update features in marketplaces provide attackers a direct channel to all installed clients.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
