GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply chain worm hits Microsoft's Python SDK

TL;DR AI
2 min readKey summary
GitHub confirmed a poisoned VS Code extension on an employee’s device exposed about 3,800 internal repositories.
The breach is tied to TeamPCP, also tracked as UNC6780, a financially motivated group behind the Mini Shai-Hulud worm.
The same actor is running a broader supply-chain campaign across npm and PyPI, including other package compromises.
The incident highlights how one compromised developer tool can reveal internal code and infrastructure details at scale.
