<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(sophos.com) GitHub Confirms Internal Breach via Malicious VS Code Extension by TeamPCP Threat Actor]]></title><description><![CDATA[<p>(sophos.com) GitHub Confirms Internal Breach via Malicious VS Code Extension by TeamPCP Threat Actor</p><p>GitHub confirmed an internal breach by TeamPCP/UNC6780 via a trojanized VS Code extension, leading to the theft of 3,800 internal repositories. No customer data was impacted, but stolen code was listed for sale on cybercrime forums.</p><p>In brief - GitHub suffered an internal breach after a malicious VS Code extension harvested credentials, enabling threat actor TeamPCP to exfiltrate 3,800 proprietary repositories. The incident underscores risks in developer tooling and supply chain security.</p><p>Technically - TeamPCP gained initial access via a malicious VS Code extension (T1555/T1003), harvesting credentials to clone internal repos (T1078). The actor abused CI/CD pipelines (T1608.004) and used self-propagating malware like CanisterWorm (T1210/T1105). GitHub mitigated by rotating secrets, isolating endpoints, and removing the extension. Recommendations include auditing IDE extensions, hunting for anomalies, and enforcing short-lived tokens.</p><p>Source: <a href="https://www.sophos.com/en-us/blog/github-internal-repositories-breached" rel="nofollow noopener"><span>https://www.</span><span>sophos.com/en-us/blog/github-i</span><span>nternal-repositories-breached</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/8632dea2-740e-4dde-aded-213179eb08bc/sophos.com-github-confirms-internal-breach-via-malicious-vs-code-extension-by-teampcp-threat-actor</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 08:07:34 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8632dea2-740e-4dde-aded-213179eb08bc.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 May 2026 14:02:35 GMT</pubDate><ttl>60</ttl></channel></rss>