GitHub is investigating unauthorized access to its internal repositories after TeamPCP claimed to have accessed approximately 4,000 repositories containing private code. The claim follows the group's history of supply chain attacks on GitHub, PyPI, NPM, Docker and other platforms including the recent Trivy and LiteLLM compromises.

GitHub is looking into claims by the TeamPCP hacking collective that it gained entry to roughly 4,000 of the company’s private internal code repositories.
The firm’s cloud-based development service supports more than 4 million organizations, including 90% of the Fortune 100, along with over 180 million developers who help maintain more than 420 million repositories.
As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free.
GitHub told BleepingComputer it has “no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories)” while it continues to watch its infrastructure for any further suspicious activity. The company added that any customers found to be affected will receive notifications through its standard incident-response procedures.
On the Breached forum Tuesday, TeamPCP posted that it had obtained “Github’s source code and internal orgs” and demanded payment of at least $50,000. The group stated, “No low ball offers will be accepted, everything for the main platform is there and I very am happy to send samples to interested buyers to verify the absolute authenticity. There is a total of around ~4,000 repos of private code here.”
TeamPCP continued, “As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free. If you are interested. Send your offers to the communications below, we are not interested in under 50k, the best offer will get it.”
The Trivy breach also affected the LiteLLM open-source Python library in an attack that infected tens of thousands of devices with its "TeamPCP Cloud Stealer" information-stealing malware.
The collective has been tied to earlier supply-chain intrusions aimed at several major developer platforms such as GitHub, PyPI, NPM, and Docker. In March it breached Aqua Security’s Trivy vulnerability scanner; that incident is thought to have triggered follow-on compromises of Aqua Security Docker images and the Checkmarx KICS project.
The same Trivy compromise also hit the LiteLLM open-source Python library, delivering the group’s “TeamPCP Cloud Stealer” information-stealing malware to tens of thousands of devices. More recently TeamPCP was connected to the “Mini Shai-Hulud” supply-chain operation, which reached devices belonging to two OpenAI employees, and it threatened to publish Mistral AI source code obtained through stolen CI/CD credentials.
Update May 20, 04:17 EDT: GitHub has now confirmed the breach of ~3,800 internal repositories after an employee installed a malicious VS Code extension.
Expert Take: Cloud administrators should audit CI/CD credentials and scanner tool integrity across their supply chains to limit exposure to repeated TeamPCP-style attacks.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Amazon is scaling Prime Air drone deliveries to nearly 500 locations while Anduril targets 1,000 engineers in Seattle and a reporter's AirTag exposed a hidden book-scanning site used for AI data. These stories illustrate the intersection of logistics, defense tech, and AI infrastructure demands in 2026.
CISA added the actively exploited CVE-2026-69836 deserialization vulnerability in Microsoft Entra ID to its Known Exploited Vulnerabilities catalog on 2026-08-21 with a federal remediation deadline of 2026-08-24. The CVSS 10.0 flaw, already mitigated server-side by Microsoft, allows unauthenticated remote code execution and requires no customer action.
Samsung Electronics expects 90 trillion won to 110 trillion won available for shareholder returns in 2026, labeling the amount the largest ever by a Korean company. The disclosure follows SK Hynix's buyback announcement and reflects the windfall from AI-fueled memory chip sales.