Skip to content

GitHub

Disclosed May 20, 20264 months agoConfirmed

Official notice

GitHub says 3,800 internal repositories stolen via poisoned Nx Console extension

GitHub said attackers accessed about 3,800 internal repositories after an employee installed a malicious Nx Console VS Code extension version tied to the TanStack npm supply-chain attack. TeamPCP demanded a ransom; GitHub found no evidence customer data outside those repos was stolen.

What is known

People affectedNot stated in the sources we have
DisclosedMay 20, 2026
AttackSupply chain
Data exposedSource code, Credentials and tokens, API keys
SectorTech · US
StatusConfirmed
Part ofTanstack (2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 20

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about GitHub

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.