Categories
News

GitHub confirms 3,800 inside repos stolen by way of poisoned VS Code extension as provide chain worm hits Microsoft’s Python SDK

Source link : https://tech365.info/github-confirms-3800-inside-repos-stolen-by-way-of-poisoned-vs-code-extension-as-provide-chain-worm-hits-microsofts-python-sdk/

GitHub confirmed on Could 20 {that a} poisoned VS Code extension put in on an worker’s machine gave attackers entry to roughly 3,800 inside repositories on the Microsoft-owned code storage and authorship platform.

The risk group TeamPCP, formally tracked by Google Menace Intelligence Group as UNC6780, claimed duty and is promoting the stolen repositories on the market beginning at $50,000. GitHub’s evaluation: the attacker’s declare is “directionally consistent” with the investigation to this point. Pattern Micro, StepSecurity, and Snyk have formally tracked TeamPCP throughout not less than seven waves of the Mini Shai-Hulud provide chain worm since March.

The GitHub breach didn’t land in isolation. It arrived the identical day a brand new Mini Shai-Hulud wave cast legitimate cryptographic provenance on 639 malicious npm package deal variations, at some point after attackers compromised a VS Code extension with 2.2 million installs, the identical day Wiz found TeamPCP had compromised Microsoft’s durabletask Python SDK on PyPI, and the identical morning Verizon’s 2026 DBIR revealed that 67% of staff entry AI instruments by way of non-corporate accounts. 5 provide chain surfaces failed in 48 hours. Two extra AI-agent assault courses have been disclosed the identical month that accomplished the grid. One group connects not less than three of them.

GitHub confirms the breach, names the assault vector, and the attribution path is lengthy

“Yesterday we…

—-

Author : tech365

Publish date : 2026-05-20 18:08:00

Copyright for syndicated content belongs to the linked Source.

—-

12345678

Exit mobile version