COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: GitHub confirms breach of 3,800 internal repos via VS Code plugin
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Binance > GitHub confirms breach of 3,800 internal repos via VS Code plugin
Binance

GitHub confirms breach of 3,800 internal repos via VS Code plugin

In Brief

  • 🚨 GitHub admits nearly 3,800 internal repositories were breached via a malicious VS Code plugin.

  • Hackers claim to possess source code and are seeking over $50,000 to sell it.

  • ⚠️ Key point: Even a single compromised supply chain tool in $BTC-linked companies can threaten entire crypto ecosystems.

İlayda Peker
İlayda Peker 2 hours ago
Share
SHARE

A recent security breach involving unauthorized access to GitHub’s internal repositories has triggered significant concern in the software development community. According to a statement released by the platform on May 20, the attack originated from a malicious Visual Studio Code extension installed on an employee’s computer.

Contents
Timeline and initial findingsOrigins and extent of the threatRising risk for crypto APIs

Timeline and initial findings

After detecting unauthorized access on May 19, GitHub acted swiftly to remove the compromised extension from its systems and deactivated related access points. The company stated that, at present, there is no direct evidence indicating that user repositories, organizational accounts, or customer data were impacted by the incident.

GitHub continues to assess the scope of the breach and is working to contain its effects. In an official update, the company confirmed that the attack was limited solely to internal repositories, with the attacker successfully accessing approximately 3,800 of them.

GitHub has urgently rotated its most sensitive credentials and access keys and will implement additional security measures as the situation becomes clearer. Current findings suggest that only non-user systems were targeted, and investigations are still ongoing.

As the inquiry proceeds, GitHub has been analyzing system logs and reviewing the effectiveness of credential resets. The company has committed to sharing a comprehensive report once its investigation concludes.

Origins and extent of the threat

The cyberattack has been linked to the well-known threat group UNC6780. According to information from Google Threat Intelligence Group, the culprits operating under the alias “TeamPCP” are notorious for conducting financially motivated supply chain attacks, focusing on infiltrating software development pipelines.

TeamPCP claims to have obtained source code and internal information from nearly 4,000 private GitHub repositories belonging to the company’s core infrastructure. Reports suggest that these stolen materials are being offered for sale at prices exceeding $50,000, with samples potentially being shared as proof.

Google’s Threat Intelligence unit emphasizes that TeamPCP specializes in compromising automated authentication procedures, software delivery chains, and developer tools to gain unauthorized access.

Earlier in 2026, the group exploited a vulnerability in the Trivy Vulnerability Scanner (CVE-2026-33634) in attacks affecting major corporations, including Cisco. They have also been linked to credential phishing campaigns targeting security software firms like LiteLLM and Checkmarx.

Glossary: UNC6780 is a threat group identified in cybersecurity research as responsible for financially driven attacks. Their operations typically target supply chains, developer tools, and automation systems to gain access to sensitive data.

Rising risk for crypto APIs

Binance founder Changpeng Zhao underscored the urgency for both developers and teams to implement immediate security measures, highlighting how this breach could ripple into the cryptocurrency sector. The heavy reliance on API infrastructures exposes organizations to chain-reaction threats.

Storing API keys, automation tokens, and CI/CD credentials inside main code repositories makes companies particularly vulnerable, as a single supply chain flaw can put multiple exchanges, custody solutions, and data services at risk.

PlatformPrimary FunctionPotential Risk
CoinStats APIPortfolio managementUser funds at risk if keys are leaked
CoinGecko APIPrice & market dataFalse pricing flows, data manipulation
InfuraBlockchain node accessService outages, network exploitation

Recently, platforms such as CoinGecko API, CoinMarketCap API, Infura, Alchemy, Kaiko, and Bitquery have gained substantial market share. Security experts advise developers to regularly audit the API backends of these tools, given their central role in both transaction monitoring and security.

Specialized platforms in software security stress that using APIs correctly and managing credentials with up-to-date best practices are crucial for sustainable crypto projects. Without such measures, similar attacks could become more common.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Binance AI blocks $10.53 billion in crypto fraud by 2026

Binance to remove multiple altcoin futures pairs after new listing decisions

Binance tightens market maker rules to strengthen transparency and protect users

Binance Launches Stock Futures Trading as Exchange Expands U.S. Equity Offerings

Binance Launches Centrifuge (CFG) Trading Pairs as It Expands Select Altcoin Offerings

İlayda Peker 20 May, 2026 - 2:39 pm 20 May, 2026 - 2:39 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Ripple Prime joins EDX for $11.5 trillion crypto access
Next Article Ethereum whales drop 7 percent as price nears $2,000
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Sorted Wallet raises $4.4 million for USDT phone transfers
Tether (USDT)
Quantum risk puts 6.04 million BTC on the line
Bitcoin (BTC)
Solana risks 30 dollar drop after support at 81.30 breaks
Solana (SOL)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?