Skip to main content

Company intelligence

Github cybersecurity incidents and threat signals

github.com

Github logo

This company page brings together public reporting currently associated with Github. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

2

Published signals

currently linked to this company

0

Last 28 days

recent published signals

1

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 29, 2026

Latest report

most recent published signal

Company signals

All published signals involving Github

Github logoUse of stolen credentials or exploit
Medium

GitHub Confirms TeamPCP Hack of Internal Environment

GitHub confirmed that TeamPCP hackers breached a limited internal environment connected to the broader TanStack supply-chain campaign. While customer repositories and production systems remained secure, the incident raised concerns over software supply-chain integrity and developer platform security. The threat actor group TeamPCP claimed responsibility for stealing approximately four thousand developer code repositories and intended to sell the stolen internal source code.

Github
Github logo
Medium

Supply Chain Attack on GitHub Action 'tj-actions/changed-files' Leaks CI/CD Secrets

A supply chain attack compromised the popular 'tj-actions/changed-files' GitHub Action, impacting over 23,000 repositories. Attackers injected malicious code that exfiltrated CI/CD secrets, GitHub tokens, API keys, and other credentials by printing them directly into workflow logs. The attack began on March 10, 2025, and was detected on March 14, 2025, with public reporting starting around March 10-14, 2025.

Github

FAQ

Questions about Github cybersecurity reporting

What does the Github page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Github.

Does every mention of Github appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.