COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: GitHub confirms breach of 3,800 internal repos via VS Code plugin
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Binance > GitHub confirms breach of 3,800 internal repos via VS Code plugin
Binance

GitHub confirms breach of 3,800 internal repos via VS Code plugin

In Brief

  • 🚨 GitHub admits nearly 3,800 internal repositories were breached via a malicious VS Code plugin.

  • Hackers claim to possess source code and are seeking over $50,000 to sell it.

  • ⚠️ Key point: Even a single compromised supply chain tool in $BTC-linked companies can threaten entire crypto ecosystems.

İlayda Peker
İlayda Peker 2 months ago
Share
SHARE

A recent security breach involving unauthorized access to GitHub’s internal repositories has triggered significant concern in the software development community. According to a statement released by the platform on May 20, the attack originated from a malicious Visual Studio Code extension installed on an employee’s computer.

Contents
Timeline and initial findingsOrigins and extent of the threatRising risk for crypto APIs

Timeline and initial findings

After detecting unauthorized access on May 19, GitHub acted swiftly to remove the compromised extension from its systems and deactivated related access points. The company stated that, at present, there is no direct evidence indicating that user repositories, organizational accounts, or customer data were impacted by the incident.

GitHub continues to assess the scope of the breach and is working to contain its effects. In an official update, the company confirmed that the attack was limited solely to internal repositories, with the attacker successfully accessing approximately 3,800 of them.

GitHub has urgently rotated its most sensitive credentials and access keys and will implement additional security measures as the situation becomes clearer. Current findings suggest that only non-user systems were targeted, and investigations are still ongoing.

As the inquiry proceeds, GitHub has been analyzing system logs and reviewing the effectiveness of credential resets. The company has committed to sharing a comprehensive report once its investigation concludes.

Origins and extent of the threat

The cyberattack has been linked to the well-known threat group UNC6780. According to information from Google Threat Intelligence Group, the culprits operating under the alias “TeamPCP” are notorious for conducting financially motivated supply chain attacks, focusing on infiltrating software development pipelines.

TeamPCP claims to have obtained source code and internal information from nearly 4,000 private GitHub repositories belonging to the company’s core infrastructure. Reports suggest that these stolen materials are being offered for sale at prices exceeding $50,000, with samples potentially being shared as proof.

Google’s Threat Intelligence unit emphasizes that TeamPCP specializes in compromising automated authentication procedures, software delivery chains, and developer tools to gain unauthorized access.

Earlier in 2026, the group exploited a vulnerability in the Trivy Vulnerability Scanner (CVE-2026-33634) in attacks affecting major corporations, including Cisco. They have also been linked to credential phishing campaigns targeting security software firms like LiteLLM and Checkmarx.

Glossary: UNC6780 is a threat group identified in cybersecurity research as responsible for financially driven attacks. Their operations typically target supply chains, developer tools, and automation systems to gain access to sensitive data.

Rising risk for crypto APIs

Binance founder Changpeng Zhao underscored the urgency for both developers and teams to implement immediate security measures, highlighting how this breach could ripple into the cryptocurrency sector. The heavy reliance on API infrastructures exposes organizations to chain-reaction threats.

Storing API keys, automation tokens, and CI/CD credentials inside main code repositories makes companies particularly vulnerable, as a single supply chain flaw can put multiple exchanges, custody solutions, and data services at risk.

PlatformPrimary FunctionPotential Risk
CoinStats APIPortfolio managementUser funds at risk if keys are leaked
CoinGecko APIPrice & market dataFalse pricing flows, data manipulation
InfuraBlockchain node accessService outages, network exploitation

Recently, platforms such as CoinGecko API, CoinMarketCap API, Infura, Alchemy, Kaiko, and Bitquery have gained substantial market share. Security experts advise developers to regularly audit the API backends of these tools, given their central role in both transaction monitoring and security.

Specialized platforms in software security stress that using APIs correctly and managing credentials with up-to-date best practices are crucial for sustainable crypto projects. Without such measures, similar attacks could become more common.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Binance partners with STOP THE TRAFFIK to fight crypto-linked human trafficking

$589 million in Bitcoin withdrawn from Binance in largest outflow since February

Binance to launch 25x leveraged SpaceX perpetual contract as SPCX slides to IPO price

Binance memecoins see $1.21 billion net outflow since Bitcoin’s October 2025 high

Binance US targets 20% market share after regulatory case closed

İlayda Peker 20 May, 2026 - 2:39 pm 20 May, 2026 - 2:39 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
The author, who holds a degree in International Relations and Political Science, has 10 years of experience as a writer and editor in the fields of cryptocurrency, blockchain technologies, and digital asset markets.While at COINTURK, he has published over 8,500 news articles, analyses, essays, and reports on Bitcoin, altcoins, cryptocurrency markets, the blockchain ecosystem, digital asset regulations, and global financial developments. Closely following market movements and industry developments, the author addresses the complex world of cryptocurrency in a clear and reader-friendly manner.An avid reader, the author also evaluates the impact of international developments on financial markets and the digital asset ecosystem.
Previous Article Ripple Prime joins EDX for $11.5 trillion crypto access
Next Article Ethereum whales drop 7 percent as price nears $2,000
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Ripple website does not forecast $349 XRP price, community members clarify
Ripple (XRP)
Poolin files for Chapter 11 bankruptcy, lists $173 million debt and plans Texas asset sale
Bitcoin (BTC)
Ethereum recovers from 6 month slump, targets $1,935 resistance
Ethereum (ETH)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?