GitHub internal repos breached
GitHub confirms internal repositories were accessed via a compromised VS Code extension, with no evidence of customer data being affected.
3 min read

Visual TL;DR
third-party VS Code extension published with malicious code
From the articleThe breach, detected on May 18th, originated from a poisoned VS Code extension published by a third party.
From the article 2 mentionsGitHub is investigating an unauthorized access incident that compromised its internal repositories.
From the articleAccording to a blog post from the company, the malicious extension version was removed, and the affected employee device was isolated immediately.
affected employee device was isolated to prevent further spread
From the articleAccording to a blog post from the company, the malicious extension version was removed, and the affected employee device was isolated immediately.
activity involved exfiltration of GitHub-internal repositories only
no evidence of customer data being affected outside internal systems
From the article 2 mentionsCrucially, the company states there is no evidence of impact to customer information stored outside of GitHub's internal systems, such as customer enterprises, organizations, and repositories.
From the articleHowever, some internal repositories did contain excerpts of customer support interactions.
customers will be notified if any impact is discovered
© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.