Get all your news in one place.
100's of premium titles.
One app.
Start reading
International Business Times
International Business Times

500 Poisoned Packages, Hundreds of Companies: TeamPCP's Worm Just Reached GitHub

A GitHub employee installed a routine VS Code extension update on the morning of May 18, 2026. That single action handed cybercrime group TeamPCP enough access to exfiltrate approximately 3,800 of GitHub's internal source code repositories — everything from platform infrastructure to proprietary tooling built by the company that hosts more than 420 million repositories for over 180 million developers worldwide. GitHub confirmed the intrusion on May 20 and said it detected the compromise the previous day.

GitHub CISO Alexis Wales named the specific extension on May 21: Nx Console v18.95.0, a widely used tool for managing Angular and React projects carrying a verified publisher badge and 2.2 million installs. The poisoned build was live on Microsoft's Visual Studio Marketplace for only 18 minutes before the community caught it — but 18 minutes was enough. GitHub contained the compromised endpoint, rotated critical secrets, and said it has no current evidence that customer code was affected. The investigation remains ongoing.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.