Hacker Group TeamPCP Breaches GitHub in Latest Wave of Open Source Supply Chain Attacks

GitHub disclosed in May 2026 that hackers breached its systems after a developer installed a malicious extension for VSCode, a widely used code editor owned by Microsoft. The attackers, a cybercriminal group called TeamPCP, claim to have accessed around 4,000 of GitHub’s internal code repositories. GitHub confirmed at least 3,800 compromised repositories, stating that all contained GitHub’s own code rather than customer data.

TeamPCP announced the breach on BreachForums, a criminal marketplace, advertising GitHub’s source code and internal organization data for sale. “We are here today to advertise GitHub’s source code and internal orgs for sale,” the group wrote, adding that it would provide samples to prospective buyers.

The GitHub incident is the latest in what cybersecurity firm Socket describes as the longest-running software supply chain attack spree on record. In recent months alone, TeamPCP has conducted 20 distinct “waves” of attacks, hiding malware in more than 500 separate pieces of software — over a thousand when counting all affected versions. Previous victims include AI firm Anthropic and data contracting firm Mercor.

TeamPCP’s method follows a self-reinforcing cycle: hackers infiltrate a network developing a widely used open source tool, plant malware that spreads to other developers’ machines, then steal credentials to publish further poisoned software. “It’s a flywheel of supply chain compromises,” said Ben Read, who leads strategic threat intelligence at cloud security firm Wiz. “It’s self-perpetuating, and it’s been a hugely successful way to get access to networks and steal stuff.”

The group has also reportedly automated much of this process using a self-spreading worm called Mini Shai-Hulud, named after references to the sci-fi novel Dune embedded in GitHub repositories the worm creates. The repositories store encrypted stolen credentials and include the phrase “A Mini Shai-Hulud Has Appeared.”

The scale and pace of TeamPCP’s activity suggests the threat to organizations that rely on open source software development tools may continue to grow. Read noted that while the GitHub breach may be the group’s largest to date, each individual compromise represents a significant event for the affected organization.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top