GitHub opened a public incident thread on May 20, 2026, describing unauthorized access to its internal repositories after attackers compromised an employee device through a poisoned Visual Studio Code extension. The company said it removed the malicious extension build, isolated the endpoint, and activated incident response.
The first post did not quantify end-user impact or confirm exposure of customer repositories on github.com—BreachHistory tracks this as a corporate and developer-tooling supply-chain event pending further thread updates.
Canonical record: GitHub internal repositories VS Code incident 2026 on BreachHistory.
Source: GitHub on X