Internal GitHub Repositories Exposed In Breach Claims, TeamPCP Seeks More Than $50,000

A claim circulating in cybersecurity circles says GitHub’s internal codebase has been exposed and offered for sale, but the platform says its own investigation has not found evidence that customer data outside internal repositories was affected. The case has drawn unusual attention because GitHub sits at the center of global software development.

The group behind the claim is known as TeamPCP. It says it gained access to GitHub’s internal systems and obtained proprietary organizational data as well as source code that powers the platform.

Dark Web Informer reported that TeamPCP asked for more than $50,000 for a dataset it described as containing around 4,000 private repositories tied to GitHub’s core platform. In a later update, GitHub said the figure of about 3,800 repositories was broadly consistent with its own internal findings.

Repositories are project folders that preserve the full history of code changes. If such material is truly reached by malicious actors, it can give them valuable insight into how a system is built and where new weaknesses might exist.

TeamPCP also reportedly shared file listings and screenshots showing repository archive names. The group said it was prepared to provide samples to serious buyers as proof that the data was genuine.

GitHub acknowledged on X that unauthorized access had occurred inside its internal repositories. At the same time, the company said it had not found evidence that customer information stored outside those internal repositories was impacted, including data tied to enterprises, organizations, and customer repositories.

The company added that it continues to monitor its infrastructure for any further activity. It also said it would use its existing incident-response and notification channels if evidence later shows customer impact.

In a follow-up update, GitHub said it had detected and contained a compromise on a single employee device. The incident involved a malicious Microsoft Visual Studio Code extension that had been tampered with.

According to GitHub, the harmful extension version has been removed and the affected endpoint has been isolated. The company said incident response began as soon as the issue was identified and that a more complete report will be released after the investigation ends.

Google Threat Intelligence Group tracks TeamPCP under the name UNC6780. The group is commonly described as financially motivated and linked to software supply chain attacks targeting open-source packages.

That history includes previous incidents involving Trivy Vulnerability Scanner, Checkmarx, and LiteLLM. For security researchers, that background makes the latest claim involving GitHub difficult to dismiss.

TeamPCP also said it was not trying to extort GitHub. In posts that circulated online, the group claimed it would destroy the data on its side if only one buyer came forward, but would leak it for free if no one purchased it.

An account on X believed to be tied to TeamPCP later accused GitHub of delaying public notification. That accusation has not changed GitHub’s official position, which remains that the investigation is ongoing and that customer exposure has not been confirmed.

GitHub’s role in the software ecosystem is what makes the incident especially sensitive. Even if customer repositories are not involved, access to internal code can still provide attackers with technical clues that are useful for finding new weaknesses.

For now, the central facts remain unchanged: GitHub says there was unauthorized access to internal repositories, a compromise on one employee device was contained, and there is still no evidence that customer data was affected beyond the internal GitHub repositories under review.

Source: www.indiatoday.in
Related