Command Palette
Search for a command to run...

GitHub Ties 3,800 Internal Repo Breach to TanStack npm Supply-Chain Attack

techcybersecurity 59 posts · 30 accounts

GitHub has linked the breach of about 3,800 internal repositories to the TanStack npm supply-chain attack, saying attackers used a malicious Nx Console Visual Studio Code extension. The company previously said it detected and contained the compromise on an employee device, removed the malicious extension version and isolated the endpoint.

GitHub said its assessment was that only GitHub-internal repositories were exfiltrated and that the attacker’s claim of roughly 3,800 repositories was directionally consistent with its investigation. The company also said it rotated critical secrets and had no evidence that customer information stored outside its internal repositories, including customer enterprises, organizations and repositories, was affected.

From the sources (25 posts)

@darkwebinformer

🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data. The actor claims the dataset in

@darkwebinformer

RT @DarkWebInformer: 🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed A threat actor using…

@alvierid

RT @H4ckmanac: 🚨Data Breach Alert ‼️ 𝗧𝗲𝗮𝗺𝗣𝗖𝗣 𝗖𝗹𝗮𝗶𝗺𝘀 𝗦𝗮𝗹𝗲 𝗼𝗳 𝗚𝗶𝘁𝗛𝘂𝗯 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝗹 𝗦𝗼𝘂𝗿𝗰𝗲 𝗖𝗼𝗱𝗲 TeamPCP hacking group claimed the compromise and…

@github

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organiza

@github

If any impact is discovered, we will notify customers via established incident response and notification channels.

@tayvano_

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@darkwebinformer

🚨 GitHub is investigating the unauthorized access claim to it's internal repositories.

@degeneratenews

BREAKING: @github SAYS "WE ARE INVESTIGATING UNAUTHORIZED ACCESS TO GITHUB’S INTERNAL REPOSITORIES. WHILE WE CURRENTLY HAVE NO EVIDENCE OF IMPACT TO CUSTOMER INFORMATION STORED OUTSIDE OF GITHUB’S INTERNAL REPOSITORIES... WE ARE CLOSELY MON

@feross

👀

@zachtratar

It’s important for all software companies to be extremely defensive and safe right now. Assume most packages will get pwned. Reduce platform risk. Reduce code storage, deployment surface area. With today’s GitHub announcement, even the bi

@theo

It would be really funny if Github itself got pwn'd by one of the NPM package takeovers

@suppvalen

uhm..

@andersonbcdefg

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@cointelegraph

🚨 ALERT: GitHub is investigating unauthorized access to its internal repositories, saying there is currently no evidence of impact to customer data stored outside of GitHub's systems.

@polymarket

JUST IN: GitHub announces it is investigating unauthorized access to its internal repositories.

@mikko

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@hakluke

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@andrewcurran_

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@cz_binance

If you have API keys in your code, even private repos, now is the time to double check and change them...

@mtslive

SITUATION DETECTED: GitHub is investigating unauthorized access to its internal repositories. The company says it has no evidence of impact to customer data at this time.

@stevibe

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@alvierid

RT @github: We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to cu…

@ryancarson

If you have ANY private repos with plain text secrets or sensitive documents/architectures, immediately rotate your secrets

@degeneratenews

NEW: @cz_binance SAYS “IF YOU HAVE API KEYS IN YOUR CODE, EVEN PRIVATE REPOS, NOW IS THE TIME TO DOUBLE CHECK AND CHANGE THEM…​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​“ - FOLLOWING REPORTED @github INCIDENT

@mattjay

Sigh

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive