chiprook
← Security
SecuritySeptember 24, 2026, 15:32

GitHub lost 3,800 repos after malicious VSCode extension

GitHub confirmed that roughly 3,800 internal repositories were exfiltrated after an employee installed a trojanised version of the Nx Console extension from the official VS Code Marketplace. The campaign has been linked to the TanStack npm supply chain attack, the poisoned extension was removed, and the TeamPCP group is asking $50,000 for the dump. No customer data is known to have leaked.

GitHub lost 3,800 repos after malicious VSCode extension
#GitHub#Microsoft#VSCode#Nx
Read next
Security

Astrana Health breach: social engineering led to data theft

Security

Over 75% of Organizations Hit by Microsoft 365 Governance Issues

Security

Scan finds working service_role key in git for 58 of 154 public Supabase apps

Security

Mullvad leak: only 284 exit-IP combinations instead of trillions