The company traced the incident to a “poisoned” VS Code extension on an employee’s device. While the hacking group TeamPCP has claimed responsibility for the breach, GitHub says it has since removed the malicious extension and that the exfiltration was limited to internal data, as reported by Bleeping Computer. [Link: GitHub confirms breach of 3,800 repos via malicious VSCode extension | https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/ | BleepingComputer]

GitHub blamed the latest in a growing list of hacks claimed by TeamPCP on a poisoned VS Code extension.

A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a poisoned VS Code extension.