{"id":979,"date":"2026-05-20T04:35:04","date_gmt":"2026-05-20T04:35:04","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=979"},"modified":"2026-05-20T04:35:04","modified_gmt":"2026-05-20T04:35:04","slug":"github-investigating-teampcp-claimed-breach-of-4000-internal-repositories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=979","title":{"rendered":"GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 20, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cloud Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgoDiyeJZY33dxAsa8qElLYXNILLDT4NhloINZiuzcx3La2JvDK_d54kM8qsx_obt8vQ3FpTJr2ZVoMYiEcqHN0sbt-1A_MHlS7mSavlbDiEDg42HN1d4wCffs7ytuZhDvmMjuej5oljVIqIuRezyZCLmafRclN3wNBKcboV-19F0VMMBkVsQZckV5UaiiH\/s1700-e365\/github.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>GitHub on Tuesday said it&#8217;s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform&#8217;s source code and internal organizations for sale on a cybercrime forum.<\/p>\n<p>\u00abWhile we currently have no evidence of impact to customer information stored outside of GitHub&#8217;s internal repositories (such as our customers&#8217; enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity,\u00bb the Microsoft-owned subsidiary <a href=\"https:\/\/x.com\/github\/status\/2056884788179726685\">said<\/a>.<\/p>\n<p>The company also noted that it will notify customers via established incident response and notification channels if any impact is discovered.<\/p>\n<p>The development comes after TeamPCP, a threat actor behind a string of software supply chain attacks targeting open-source packages, listed GitHub&#8217;s source code for sale for an asking price of no less than $50,000. The alleged data dump is said to include about 4,000 repositories.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abAs always, this is not a ransom,\u00bb the group said in a post, <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2056831051742527507\">according to screenshots<\/a> shared by Dark Web Informer. \u00abWe do not care about extorting GitHub, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found, we leak it for free.\u00bb<\/p>\n<h3>TeamPCP Compromises durabletask PyPI Package<\/h3>\n<p>News of the sale comes as TeamPCP&#8217;s self-replicating malware campaign, known as Mini Shai-Hulud, continues to expand in reach with the compromise of durabletask, an official Microsoft Python client for the Durable Task workflow execution framework. Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.<\/p>\n<p>\u00abThe attacker compromised a GitHub account via a previous attack, dumped GitHub secrets from a repository to which the user had access, and from there had access to the PyPi token to publish directly,\u00bb Google-owned Wiz <a href=\"https:\/\/www.wiz.io\/blog\/durabletask-teampcp-supply-chain-attack\">said<\/a>.<\/p>\n<p>The payload embedded into the package is a dropper, which is configured to fetch and run a second-stage payload (\u00abrope.pyz\u00bb) from an external server (\u00abcheck.git-service[.]com\u00bb). The malware is assessed to be an evolution of the payload deployed in connection with the compromise of the guardrails-ai package last week.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHBPAvTjqSKkmsWL6htHglfONKxWRlMxkN39FMW8MfDgpUwqCxrp8xTGg_N7xrv212054zvl3OttJwv6xVWcY3intJhnH6VF65yd5qf2od8NCAR97aEoP7M4WAoLflM0JBaucHcMCoHM_5AWG3KNWasGkv85Tp0dAS9gFh2lZtmrTyg7sab6yXcNHKM3uK\/s1700-e365\/payload.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHBPAvTjqSKkmsWL6htHglfONKxWRlMxkN39FMW8MfDgpUwqCxrp8xTGg_N7xrv212054zvl3OttJwv6xVWcY3intJhnH6VF65yd5qf2od8NCAR97aEoP7M4WAoLflM0JBaucHcMCoHM_5AWG3KNWasGkv85Tp0dAS9gFh2lZtmrTyg7sab6yXcNHKM3uK\/s1700-e365\/payload.png\" alt=\"\" border=\"0\" data-original-height=\"2736\" data-original-width=\"1567\"\/><\/a><\/div>\n<p>Specifically, it&#8217;s designed to activate a full-featured infostealer that&#8217;s capable of harvesting credentials associated with major cloud providers, password managers, and developer tools, and exfiltrating the data to the attacker-controlled domain. It&#8217;s worth noting that the stealer is configured to execute only on Linux systems.<\/p>\n<p>According to <a href=\"https:\/\/safedep.io\/malicious-durabletask-pypi-supply-chain-attack\/\">SafeDep<\/a>, the 28KB Python stealer also attempts to read HashiCorp Vault KV secrets, unlock and dump 1Password and Bitwarden password vaults, and access SSH keys, Docker credentials, VPN configurations, and shell history.<\/p>\n<p>\u00abIf the machine is running inside AWS, it propagates itself to other EC2 instances using SSM. If it&#8217;s inside Kubernetes, it propagates through kubectl exec,\u00bb Aikido Security <a href=\"https:\/\/www.aikido.dev\/blog\/durabletask-package-compromised-mini-shai-hulud\">said<\/a>. \u00abAnd if it detects Israeli or Iranian system settings, there&#8217;s a 1-in-6 chance it plays audio and then runs rm -rf \/*.\u00bb<\/p>\n<p>\u00abAfter enumerating SSM-managed instances, it uses SendCommand with the AWS-RunShellScript document to execute the rope.pyz payload on up to 5 other EC2 instances per profile,\u00bb per <a href=\"https:\/\/www.stepsecurity.io\/blog\/microsofts-durabletask-pypi-package-compromised-in-supply-chain-attack#c2-infrastructure\">StepSecurity<\/a>. \u00abThe propagation script downloads the payload from the primary C2, falling back to the secondary domain t.m-kosche[.]com, and runs it in the background.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Also notable is the use of the FIRESCALE mechanism to identify a backup command-and-control (C2) address in the event the primary domain is unreachable. It does this by searching GitHub&#8217;s public commit messages for the pattern \u00abFIRESCALE <base64_url>.<base64_signatue>\u00bb and extracting the C2 information from it. Details of this technique were previously highlighted by Hunt.io.<\/base64_signatue><\/base64_url><\/p>\n<p>Because the worm propagates using tokens stolen from infected environments, the number of affected packages is expected to grow. Any machine or pipeline that installed an affected version of the package should be treated as fully compromised.<\/p>\n<p>\u00abThe package is downloaded roughly 417,000 times a month, and the malicious code runs automatically the moment the package is imported, with no error messages and no visible signs of compromise,\u00bb Endor Labs researcher Peyton Kennedy <a href=\"https:\/\/www.endorlabs.com\/learn\/trojanized-microsoft-sdk-durabletask-1-4-1-through-1-4-3-deliver-credential-stealing-malware\">said<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 20, 2026Malware \/ Cloud Security GitHub on Tuesday said it&#8217;s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform&#8217;s&hellip;<\/p>\n","protected":false},"author":1,"featured_media":980,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[278,1736,71,1737,663,1738,855],"class_list":["post-979","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-breach","tag-claimed","tag-github","tag-internal","tag-investigating","tag-repositories","tag-teampcp"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/979","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=979"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/979\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/980"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}