A GitHub employee installed a routine VS Code extension update on the morning of May 18, 2026. That single action handed cybercrime group TeamPCP enough access to exfiltrate approximately 3,800 of GitHub's internal source code repositories — everything from platform infrastructure to proprietary tooling built by the company that hosts more than 420 million repositories for over 180 million developers worldwide. GitHub confirmed the intrusion on May 20 and said it detected the compromise the previous day.
GitHub CISO Alexis Wales named the specific extension on May 21: Nx Console v18.95.0, a widely used tool for managing Angular and React projects carrying a verified publisher badge and 2.2 million installs. The poisoned build was live on Microsoft's Visual Studio Marketplace for only 18 minutes before the community caught it — but 18 minutes was enough. GitHub contained the compromised endpoint, rotated critical secrets, and said it has no current evidence that customer code was affected. The investigation remains ongoing.