TeamPCP breaches GitHub, accessing 3,800 internal code repositories
Source: Cryptobriefing
Published:
<p>A malicious VS Code extension gave attackers access to source code for GitHub Actions, Copilot, and CodeQL, now being shopped on underground markets for at least $50K.</p> <p>A threat group called TeamPCP gained access to roughly 3,800 of GitHub’s internal code repositories after compromising an