GitHub Internal Repo Breach Linked to Nx Console Extension That May Have Reached 6,000 Installs
GitHub said a poisoned Visual Studio Code extension on an employee device was behind unauthorized access to its internal repositories. The company said it detected and contained the compromise, removed the malicious extension version and isolated the endpoint, and that its current assessment is that only GitHub-internal repositories were exfiltrated. GitHub said the attacker’s claim of about 3,800 repositories was directionally consistent with its investigation and that critical secrets were rotated, while adding that it had no evidence customer information stored outside those internal repositories was affected.
Subsequent disclosures tied the malicious extension to Nx Console version 18.95.0. Nx said Microsoft had initially indicated 28 installs of the compromised version, but the company’s own analytics suggest it may have reached more than 6,000 users during an 11-minute window on May 18, almost all through VS Code. Dark-web monitoring reports also said TeamPCP had offered the allegedly stolen GitHub internal repositories for sale on a cybercrime forum for at least $50,000 and that the listing was later promoted jointly with LAPSUS$.
From the sources (25 posts)
@thehackersnews🚨 Hackers turned supply chain attacks into a $1,000 competition. TeamPCP just open-sourced their Shai-Hulud worm and partnered with Breached forum. Biggest haul (by downloads) wins Monero prize. Even small packages count. GitHub version a
@darkwebinformer🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data. The actor claims the dataset in
@darkwebinformerRT @DarkWebInformer: 🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed A threat actor using…
@alvieridRT @H4ckmanac: 🚨Data Breach Alert ‼️ 𝗧𝗲𝗮𝗺𝗣𝗖𝗣 𝗖𝗹𝗮𝗶𝗺𝘀 𝗦𝗮𝗹𝗲 𝗼𝗳 𝗚𝗶𝘁𝗛𝘂𝗯 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝗹 𝗦𝗼𝘂𝗿𝗰𝗲 𝗖𝗼𝗱𝗲 TeamPCP hacking group claimed the compromise and…
@githubWe are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organiza
@githubIf any impact is discovered, we will notify customers via established incident response and notification channels.
@tayvano_RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@darkwebinformer🚨 GitHub is investigating the unauthorized access claim to it's internal repositories.
@degeneratenewsBREAKING: @github SAYS "WE ARE INVESTIGATING UNAUTHORIZED ACCESS TO GITHUB’S INTERNAL REPOSITORIES. WHILE WE CURRENTLY HAVE NO EVIDENCE OF IMPACT TO CUSTOMER INFORMATION STORED OUTSIDE OF GITHUB’S INTERNAL REPOSITORIES... WE ARE CLOSELY MON
@feross👀
@zachtratarIt’s important for all software companies to be extremely defensive and safe right now. Assume most packages will get pwned. Reduce platform risk. Reduce code storage, deployment surface area. With today’s GitHub announcement, even the bi
@theoIt would be really funny if Github itself got pwn'd by one of the NPM package takeovers
@suppvalenuhm..
@andersonbcdefgRT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@cointelegraph🚨 ALERT: GitHub is investigating unauthorized access to its internal repositories, saying there is currently no evidence of impact to customer data stored outside of GitHub's systems.
@polymarketJUST IN: GitHub announces it is investigating unauthorized access to its internal repositories.
@mikkoRT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@haklukeRT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@andrewcurran_RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@cz_binanceIf you have API keys in your code, even private repos, now is the time to double check and change them...
@mtsliveSITUATION DETECTED: GitHub is investigating unauthorized access to its internal repositories. The company says it has no evidence of impact to customer data at this time.
@stevibeRT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@alvieridRT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…
@ryancarsonIf you have ANY private repos with plain text secrets or sensitive documents/architectures, immediately rotate your secrets
@degeneratenewsNEW: @cz_binance SAYS “IF YOU HAVE API KEYS IN YOUR CODE, EVEN PRIVATE REPOS, NOW IS THE TIME TO DOUBLE CHECK AND CHANGE THEM…“ - FOLLOWING REPORTED @github INCIDENT