Ad

Follow Us:
9,601 views
On Tuesday, GitHub confirmed it was investigating a security breach after a hacking group claimed to have accessed its source code. The group, known as TeamPCP, said it had breached GitHub’s internal systems and obtained proprietary organization data and source code. GitHub, owned by Microsoft, hosts source code for a significant portion of global software projects.
TeamPCP posted online that it was selling the alleged dataset for over $50,000. The group claimed the data included about 4,000 private repositories from GitHub’s main platform. According to Dark Web Informer, TeamPCP also published screenshots and a public file list to support its claims. The group stated it would provide samples to serious buyers to prove the authenticity of the data.
GitHub responded on X, stating it was investigating the incident and that only its own internal data was likely accessed. The company said there was no current evidence that user data or customer repositories outside GitHub’s internal systems were affected. GitHub assured users it was monitoring its infrastructure for any further suspicious activity.
The group behind the breach, TeamPCP, is tracked by Google Threat Intelligence Group as UNC6780. TeamPCP is known for financially motivated attacks, particularly those targeting software supply chains and open-source packages. In early 2026, the group was linked to attacks involving the Trivy Vulnerability Scanner, Checkmarx, and LiteLLM.
GitHub confirmed that an employee device had been compromised through a malicious Microsoft Visual Studio Code extension. The company reported that it removed the malicious extension, isolated the affected device, and began incident response procedures immediately. GitHub stated that the attacker’s claim of approximately 3,800 repositories accessed was consistent with its ongoing investigation.
The company emphasized that it would notify customers through established incident response channels if any impact to customer data was discovered. GitHub also stated it would release a fuller report after completing its investigation.
TeamPCP claimed that if it did not find a buyer for the stolen data, it would release the information online for free. The group stated, "As always, this is not a ransom. We do not care about extorting GitHub, 1 buyer and we shred the data on our end." TeamPCP also posted messages on X, criticizing GitHub’s handling of the incident and communication with users.
This breach raises concerns about potential cybersecurity risks if the source code is exposed. Access to internal repositories could allow malicious actors to identify and exploit vulnerabilities in GitHub’s platform. GitHub continues to monitor its systems and has committed to transparency as the investigation progresses.





View All

Samsung Galaxy Buds 4 Pro Review: क्या ₹22,999 में मिलते हैं सबसे बेहतरीन प्रीमियम वायरलेस ईयरबड्स?

कंटेंट क्रिएटर के लिए सबसे दमदार बैटरी लाइफ वाले Windows लैपटॉप, 18 घंटे की मिलेगी बैटरी लाइफ

Samsung Galaxy S26 Ultra क्यों है साल का सबसे बेहतरीन स्मार्टफोन? जानें 5 बड़े कारण

MacBook Neo Review: सस्ता नहीं, Apple का मास्टरस्ट्रोक है ये Laptop!

Samsung Galaxy S26 Ultra Review: AI से लेकर प्राइवेसी डिस्प्ले है सबसे खास, जानें कैसी है परफॉरमेंस

Vivo V70 Elite Review 2026: Price in India, Specs, Features

Raksha Bandhan Special: 6 vivo Smartphones for Every Kind of Sibling

Acer Launches New Nitro 5 Series in india starting price of 167,990

Flipkart Freedom Sale 2026 Starts August 8 With Big Discounts on Smart TVs

Samsung has unveiled its first credit card, Earn 5% back

5 Anti-Scam Tools on WhatsApp that protect you from Digital Fraud

How Samsung’s Galaxy S26 Series is Democratizing Mobile Filmmaking