Skip to main content
Featured AnalysisPrimary topicSecurity

VS Code extension compromise exposes thousands of GitHub repos; attackers sell data, CZ urges key rotation

GitHub says thousands of internal repositories were accessed after an employee workstation was compromised via a malicious VS Code extension; Binance founder Changpeng Zhao urged developers to rotate API keys immediately [1][6].

May 20, 20268:11 AMNewsroom AI

Microsoft-owned GitHub confirmed that an attacker accessed thousands of its internal repositories after compromising an employee workstation through a malicious Visual Studio Code extension, with reports identifying about 3,800 internal repositories affected. GitHub has said its initial investigation found customer repositories, enterprise accounts and organizational data remain unaffected, while the company continues to probe the incident [1] [2] [3].

A cybercrime group calling itself TeamPCP has claimed responsibility and is attempting to monetize the stolen internal data; reports say the group is seeking a minimum of $50,000 for access to the information [2] [4].

Binance founder Changpeng “CZ” Zhao publicly urged crypto developers to immediately rotate API keys and other credentials stored in code repositories and to audit secrets after the breach, citing the heightened risk to projects that leave keys in code. Security guidance from multiple outlets and GitHub itself has emphasized changing exposed credentials and rotating tokens while the investigation continues [1] [2] [5].

Developers and organizations using GitHub should assume exposed credentials may be compromised, rotate API keys and tokens, and follow official guidance from GitHub and security teams until the investigation is complete [1] [5].

Was this useful?

Anonymous signal used only for weekly cluster rankings. No public counters.

Share

Broadcast this coverage

Copy-ready links for the networks your audience checks first.

Support independent reporting

If this summary helped, a small tip helps keep ClusterWire running.

Privacy note: we log tip UI events (page + action, and article slug when applicable) to improve the feature. We don’t store IP address, user-agent, or wallet addresses in analytics. Tips are on-chain, so the sending address is public in the transaction.

Source Ledger

Citations

Follow the primary reporting behind this analysis. Click a citation to open the referenced source in a new tab.

Themes

Themes driving this story

Curated from the cluster of sources powering this article.

Security/HacksThemeExchanges/CustodyThemeInfrastructure/DevThemeMacroeconomy/MarketsThemeEthereumTheme
Live Wire

Latest Coverage

Real-time crypto intelligence ordered by publication time.

30h ago

SEC pauses plan to permit tokenized U.S. stocks over legal, operational and investor-protection concerns

The U.S. Securities and Exchange Commission has paused a planned "innovation exemption" for tokenized U.S. stocks amid legal and technical concerns, delaying regulatory clarity …

Read more
36h ago

House Oversight Demands Kalshi and Polymarket Records Amid Insider Trading Inquiry

House Oversight Committee Chair Rep. James Comer has opened a probe into alleged insider trading at prediction-market platforms Kalshi and Polymarket and has sought information …

Read more
37h ago

Intercontinental Exchange joins OKX to launch always-open Brent and WTI perpetual futures for crypto users

Intercontinental Exchange and crypto exchange OKX will list perpetual oil futures tied to ICE Brent and WTI, bringing 24/7 crude exposure to OKX users.

Read more
37h ago

Bitcoin Pizza Day 2026: Anniversary Observed as 10,000 BTC Drops $300M and Community Debates Its Legend

Bitcoin Pizza Day 2026 is being observed as the 10,000 BTC used in the original 2010 pizza purchase is roughly $300 million cheaper than a year ago [1].

Read more
40h ago

Verus recovers 4,052 ETH after negotiated bounty deal that lets exploiter keep 1,350 ETH

Verus recovered 4,052 ETH (about $8.5M) after a bounty deal that left the exploiter with 1,350 ETH [1][3][4].

Read more
40h ago

On-chain watchers flag UMA adapter exploit on Polygon; $520K-$660K traced, Polymarket says user funds safe

On-chain investigators flagged activity on Polymarket’s UMA CTF Adapter on Polygon; estimates of assets moved vary across reports while Polymarket says user funds remain safe.

Read more