GitHub
Disclosed May 20, 20264 months agoConfirmed
GitHub says 3,800 internal repositories stolen via poisoned Nx Console extension
GitHub said attackers accessed about 3,800 internal repositories after an employee installed a malicious Nx Console VS Code extension version tied to the TanStack npm supply-chain attack. TeamPCP demanded a ransom; GitHub found no evidence customer data outside those repos was stolen.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | May 20, 2026 |
| Attack | Supply chain |
| Data exposed | Source code, Credentials and tokens, API keys |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Tanstack (2026) |
Sources
| Source | |
|---|---|
| Investigating unauthorized access to GitHub's internal repositoriesgithub.blog · Official notice | Official notice |
| GitHub says hackers stole data from thousands of internal repositoriestechcrunch.com · News | News |
| GitHub links repo breach to TanStack npm supply-chain attackbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 20 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| May 164 months ago | Supply chain | Tech | Unverified | Unknown | |
| May 144 months ago | Supply chain | AI | Unverified | Unknown | |
| May 144 months ago | Supply chain | AI | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.