The GitHub Leak Situation Just Got Worse | Threat Wire

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

GitHub faced a severe week of security incidents attributed to threat actor Team PCP. The Megalodon campaign pushed 5,718 malicious commits across 5,561 repositories via compromised personal access tokens, stealing CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code. Hudson Rock analysis found 33% of attacker usernames matched known info-stealer victims. Separately, a GitHub employee downloaded a malicious VS Code extension (NX Console, poisoned via the Tanstack compromise), leading to exfiltration of ~38,000 private internal repos and customer support data. Team PCP is selling the stolen GitHub source code for a minimum of $50,000, hinting at retirement. Additional stories include a CISA contractor's public GitHub repo exposing government credentials, Discord standardizing E2E encryption for calls, and OpenAI partnering with 1Password for AI coding agent credential management.

9m watch time
104K Impressions2 Comments