GitHub has confirmed a major cyberattack that exposed data from thousands of its internal repositories. The Microsoft-owned platform said hackers accessed nearly 3,800 private repositories containing internal code and company information. However, GitHub found no evidence that attackers stole customer accounts, passwords, or public repositories.
The company has started a detailed investigation into the breach. Security teams are reviewing logs, rotating credentials, and monitoring systems for suspicious activity. GitHub also said the number of affected repositories matches the claims made by the attackers. The company plans to release a complete report after finishing the investigation.
Cybersecurity experts say hackers now target popular open-source projects and developer tools more frequently. These attacks can affect many developers and organizations at once. In recent months, hackers have targeted platforms such as LiteLLM, Trivy, Axios, and Vercel through similar supply chain attacks.
Also Read: Chongqing East Railway Station: Built by Robots in 38 Months
GitHub Around 3,800 Internal Repositories Compromised
GitHub believes the attack started after hackers compromised an employee’s device through a malicious Visual Studio Code extension. Developers widely use VS Code extensions to improve their coding environments, which makes them attractive targets for cybercriminals. Reports also claim that a hacking group called TeamPCP carried out the attack and is trying to sell the stolen data on cybercrime forums.
The GitHub breach appears linked to a larger campaign targeting software supply chains and AI-related companies. Investigators have connected TeamPCP to earlier attacks on the European Commission and the security tool Trivy. Companies linked to OpenAI have also reported malware attacks involving third-party developer tools. These incidents show how hackers exploit trusted software platforms to access sensitive systems and data.
Also Read: MS Dhoni returns to Ranchi before CSK finale

