The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via BleepingComputer

BleepingComputer · track record
78Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/GitHub Investigates TeamPCP Claimed Breach of 4,000 Internal Repos
VERIFIEDBy Xavier Rivera· ·2 min read

GitHub Investigates TeamPCP Claimed Breach of 4,000 Internal Repos

GitHub is investigating unauthorized access to its internal repositories after TeamPCP claimed to have accessed approximately 4,000 repositories containing private code. The claim follows the group's history of supply chain attacks on GitHub, PyPI, NPM, Docker and other platforms including the recent Trivy and LiteLLM compromises.

Source:BleepingComputer
Post
GitHub Investigates TeamPCP Claimed Breach of 4,000 Internal Repos
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

GitHub investigates unauthorized access to about 4,000 internal repositories after TeamPCP claims the breach and demands at least $50,000 for the data or will leak it. The company reports no evidence of customer information impact so far. This raises concerns because the group has previously conducted supply chain attacks on developer platforms like PyPI and NPM.

GitHub is looking into claims by the TeamPCP hacking collective that it gained entry to roughly 4,000 of the company’s private internal code repositories.



The firm’s cloud-based development service supports more than 4 million organizations, including 90% of the Fortune 100, along with over 180 million developers who help maintain more than 420 million repositories.


As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free.

GitHub told BleepingComputer it has “no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories)” while it continues to watch its infrastructure for any further suspicious activity. The company added that any customers found to be affected will receive notifications through its standard incident-response procedures.



On the Breached forum Tuesday, TeamPCP posted that it had obtained “Github’s source code and internal orgs” and demanded payment of at least $50,000. The group stated, “No low ball offers will be accepted, everything for the main platform is there and I very am happy to send samples to interested buyers to verify the absolute authenticity. There is a total of around ~4,000 repos of private code here.”


From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

TeamPCP continued, “As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free. If you are interested. Send your offers to the communications below, we are not interested in under 50k, the best offer will get it.”


The Trivy breach also affected the LiteLLM open-source Python library in an attack that infected tens of thousands of devices with its "TeamPCP Cloud Stealer" information-stealing malware.

The collective has been tied to earlier supply-chain intrusions aimed at several major developer platforms such as GitHub, PyPI, NPM, and Docker. In March it breached Aqua Security’s Trivy vulnerability scanner; that incident is thought to have triggered follow-on compromises of Aqua Security Docker images and the Checkmarx KICS project.



The same Trivy compromise also hit the LiteLLM open-source Python library, delivering the group’s “TeamPCP Cloud Stealer” information-stealing malware to tens of thousands of devices. More recently TeamPCP was connected to the “Mini Shai-Hulud” supply-chain operation, which reached devices belonging to two OpenAI employees, and it threatened to publish Mistral AI source code obtained through stolen CI/CD credentials.


From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

Update May 20, 04:17 EDT: GitHub has now confirmed the breach of ~3,800 internal repositories after an employee installed a malicious VS Code extension.

EXPERT TAKE

Expert Take: Cloud administrators should audit CI/CD credentials and scanner tool integrity across their supply chains to limit exposure to repeated TeamPCP-style attacks.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
githubsecuritybreachteampcpsupplychain
More fromBleepingComputer
  • Denmark CPR breach exposes data of 8.8 million people

    Tech · 3d
  • Microsoft Rolls Out Windows 11 2026 Update as Small Enablement Package

    Tech · 9d
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 1mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 34m
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 3h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 6h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Gaming· 

    Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts

    Discord server-protection bot Double Counter says an October 4 attack exposed IDs and usernames tied to up to 28 million Discord accounts, plus IP and coarse location data for about 27 million and roughly 1 million email addresses. Discord says its own platform was not breached.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.