Skip to main content
Back to overview
Medium

GitHub Confirms TeamPCP Hack of Internal Environment

GitHub confirmed that TeamPCP hackers breached a limited internal environment connected to the broader TanStack supply-chain campaign.

Key points

  • GitHub confirmed a breach of a limited internal environment by TeamPCP hackers.
  • The incident was linked to the broader TanStack supply-chain campaign.
  • Approximately 4,000 developer code repositories were allegedly stolen.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Hacking · Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data or process integrity risk

Confidentiality, Integrity

Published
May 20, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch internet-facing systems, credential abuse and exploit activity.

Business impact

Potential data or process integrity risk
Impact area
Confidentiality, Integrity
Likely asset
User or customer data

Mentioned entities

GithubData DisclosureGitHub Confirms TeamPCP Hack ofInternal Environment GitHubTeamPCPTanStackWhileGitHubApproximately

Quick context

Questions about this signal

What happened in this signal?

GitHub confirmed that TeamPCP hackers breached a limited internal environment connected to the broader TanStack supply-chain campaign. While customer repositories and production systems remained secure, the incident raised concerns over software supply-chain integrity and developer platform security. The threat actor group TeamPCP claimed responsibility for stealing approximately four thousand developer code repositories and intended to sell the stolen internal source code.

When was this signal reported?

Shadow Tier lists May 20, 2026 as the signal date.

Which organization is connected to this signal?

Github is the organization connected to this public signal.

Explore Github