In May 2026, GitHub experienced an internal data breach due to a poisoned VS Code extension. The incident involved the exfiltration of approximately 3,800 internal source code repositories, including infrastructure configurations, deployment scripts, internal API schemas, and historical commit data. GitHub confirmed that there was no evidence of impact on customer information or external data stores.
The stolen data consisted of GitHub's internal corporate estate and did not include personal data of individuals such as SSNs, medical records, or financial information. GitHub detected the breach on May 19, 2026, and identified the entry point as a backdoored Nx Console v18.95.0 VS Code extension. The investigation into the incident is ongoing, and GitHub has stated they will notify customers if any evidence of wider impact emerges; however, current indications are that the breach was confined to internal corporate systems.
Details are subject to change as the company's investigation proceeds, and official notifications may be delayed.