According to GitHub, the breach was detected on May 19 and resulted in the exfiltration of approximately 3,800 internal repositories. The company stated that, based on its current assessment, the attack affected only GitHub’s internal repositories and there is no evidence that customer information stored outside those repositories was impacted.
The hacking group TeamPCP claimed responsibility for the attack on the Breached cybercrime forum, alleging that it obtained access to GitHub source code and nearly 4,000 private repositories. The group reportedly demanded at least $50,000 for the stolen data and threatened to leak the repositories if no buyer emerged.
Cybersecurity researchers said the attack was carried out through a trojanized version of the Nx Console extension published on the Visual Studio Marketplace. The malicious extension reportedly remained available for only 18 minutes, between 12:30 PM and 12:48 PM UTC on May 18, 2026.
According to OX Security researcher Nir Zadok, the extension appeared legitimate but secretly executed a shell command on startup that downloaded and ran a hidden package from a planted commit on the official Nx GitHub repository.
The malware allegedly targeted sensitive credentials, including data from 1Password vaults, Anthropic Claude Code configurations, npm accounts, GitHub credentials and Amazon Web Services access tokens.
GitHub said it removed the malicious extension, isolated the affected endpoint and immediately launched an incident response process. The company also rotated critical secrets over Monday and Tuesday, prioritising the most sensitive credentials first.
The Nx team later confirmed that the “nrwl.angular-console” extension was compromised after one of its team member accounts was breached.
TeamPCP later claimed on social media that GitHub delayed informing users about the breach and suggested the attack was part of a broader campaign targeting trusted open-source security and development tools.
GitHub said it is continuing to analyse logs, validate credential rotations and monitor for further malicious activity, adding that a more detailed incident report will be released after the investigation is completed.

