TeamPCP gained access to GitHub's private source code after an employee unknowingly installed a malicious coding tool.

GitHub blamed the latest in a growing list of hacks claimed by TeamPCP on a poisoned VS Code extension.

A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a poisoned VS Code extension.