GitHub of a new and particularly troubling cybersecurity case, following reports that cybercriminal group TeamPCP gained access to the platform’s and attempted to sell the source code on dark web forums. The case has caused intense concern in the open source software community, as GitHub is the essential application development infrastructure for millions of developers and businesses worldwide.

Microsoft , the parent company of GitHub, has confirmed that an internal investigation into unauthorized access to private repositories is underway . According to the company, there is no indication that customer data or organizational repositories hosted on the platform were affected so far. However, real-time monitoring of the infrastructure continues as security experts try to assess the true scope of the breach.
TeamPCP at the center of the attack
The incident is believed to be the work of TeamPCP, a threat actor group that has been linked to recent attacks on the software supply chain. The group reportedly posted an ad for sale of GitHub source code, asking for at least $50,000 for access to the data.
See also: 7-Eleven data breach: ShinyHunters behind the attack?
The cybercriminals claimed to have about 4,000 internal repositories in their possession , a number that is close to GitHub's current estimates. In a public post, they stated that this was not a case of ransomware or extortion , but of pure commercial exploitation of the data . In fact, they left open the possibility of leaking the material for free if no buyer appeared.
This stance reflects a new trend in cybercrime, where groups of attackers seek profit not through encryption of systems, but through the sale of source code, credentials and internal company data.
The "poisoned" Visual Studio extension
In a later update, GitHub revealed that the initial breach appeared to be linked to an employee's device that was infected via a malicious extension for Microsoft Visual Studio. The incident is considered particularly serious because it demonstrates how even tools used by developers every day can be turned into a Trojan horse for large-scale attacks.

As an immediate response, the company has renewed critical secrets and access credentials, prioritizing high-value accounts and tokens. Analysts say such attacks highlight the security gaps that persist even in mature software development ecosystems.
New malware campaign via PyPI
Alongside the developments on GitHub, TeamPCP is reportedly expanding its activity into the Python. Specifically, malicious versions of the durabletask package, Microsoft's official Python client for the Durable Task framework, have been detected.
Versions 1.4.1, 1.4.2, and 1.4.3 contained malicious code that installed dropper malware, capable of downloading and executing a second payload from a remote server. According to security researchers at Wiz, the perpetrators gained access to the GitHub account through a previous breach, then stole access secrets, and finally published the infected package on PyPI.
See also: NYC Health and Hospitals: Data breach affects 1.8 million people
The incident is considered a typical example of a supply chain attack, a category of cyberattacks that has increased dramatically in recent years. Instead of directly targeting organizations, attackers infiltrate popular development tools, exploiting the trust that developers have in official repositories.
Credential theft and automatic propagation in cloud infrastructures
The malware detected is described as highly sophisticated. According to cybersecurity companies such as SafeDep, Aikido Security and StepSecurity, the malware primarily targets Linux environments and has the ability to collect credentials from cloud providers, password managers, SSH keys, Docker configurations, VPN settings and shell history.
Of particular concern is that the malware can automatically spread to AWS EC2 instances via AWS Systems Manager, as well as to Kubernetes clusters via kubectl exec. In this way, an initial infection can quickly escalate into a full-scale breach of an entire cloud infrastructure.
The researchers also revealed that the attackers are using a FIRESCALE-style fallback communication mechanism, which allows for the retrieval of new command-and-control addresses via public GitHub commits. This technique makes it significantly more difficult to detect and block malicious activity.

Serious risk to the open source ecosystem
Experts warn that the case may be much larger than has been revealed so far. The infected package is being downloaded hundreds of thousands of times each month, which significantly increases the number of potential victims.
Most worryingly, the malicious code is automatically executed upon package import, without any obvious error messages or warnings to the user. This means that many development teams may have already been compromised without knowing it.
See also: CISA leak: Administrator exposed AWS GovCloud keys on GitHub
This new case brings the debate around the security of the open-source ecosystem back to the fore. While open source software is a key pillar of modern technology, supply chain demonstrate that even the most popular tools can be turned into vehicles for cyberattacks.
For businesses and development teams, the message is clear: protecting credentials, controlling dependencies, and continuously monitoring infrastructure are no longer optional procedures, but critical survival requirements in the modern digital world.
