Story perspectives
GitHub Removes Malicious VS Code Extension After 3,800 Repo Breach
5/21/2026
1 of 3
GitHub Extension Theft
- GitHub confirmed a malicious VS Code extension stole data from about 3,800 internal repositories.
- GitHub isolated the compromised device, removed the extension, and rotated the exposed secrets.
- TeamPCP posted the stolen code on a forum and demanded $50,000.
- Researchers tied the extension to a brief Nx Console release that harvested credentials for GitHub, AWS, npm and other services.
- GitHub reported no evidence that customer data outside the internal repositories was affected.
1 / 3
