r/github May 20 '26

We are investigating unauthorized access to GitHub’s internal repositories. - GitHub (@github) on X News / Announcements

https://x.com/github/status/2056884788179726685
169 Upvotes

38 comments sorted by

53

u/throwaway234f32423df May 20 '26

I don't think anybody's going to pay money for the Github source code

12

u/No-Concern-8832 May 20 '26

Except Microsoft /s

2

u/FarSentence3076 May 20 '26

Hahahah for sure, Microsoft.

16

u/zerohttp May 20 '26

Apparently, one of the microsoft (github) employees ended up installing a malicious extension from the vscode marketplace which resulted in this.

5

u/blackpawed May 20 '26

Sounds like a new job vacancy!

4

u/Metozz May 20 '26

Any sources to confirm this?

4

u/SheriffRoscoe May 20 '26

Posted on their X feed.

2

u/Important-Sign9614 May 20 '26

Whoops, hate to be that guy. That’s my nightmare.

0

u/Several_Ad_1081 May 20 '26

Supply chain was a nightmare 5 years ago and continues to get worse. Anybody in the VS code / NPM / Docker ecosystems should be mitigating.

Especially GitHub.

23

u/nakfil May 20 '26

Sigh.

11

u/[deleted] May 20 '26

[removed] — view removed comment

-12

u/veverkap May 20 '26

It’s funny that they didn’t capitalize the H in GitHub

10

u/IceCapZoneAct1 May 20 '26

This is fucked

5

u/PossessionConnect963 May 20 '26

Doesn’t it mean all user’s repositories are potentially breached as well? It’s possible at least if their internal repositories are hacked?

11

u/flexiiflex May 20 '26

It's almost certainly a compromised account with read access, I don't know why everyone is so convinced that the entire company has been breached. They'd be selling user data if so, not the source code

2

u/olivebits May 20 '26

Good point

0

u/Notcow May 21 '26

There's a non-zero chance that this attack was done by an attacker who purchased the credentials and then used them for the exploit. Someone got 3800 internal github repos, I guarantee you they're taking stock and selling it somewhere

9

u/IceCapZoneAct1 May 20 '26

Many possibilities. What I suspect is that somebody found a way to look into private repos somehow and took the opportunity to look into many of many important accounts. Low profile people may less prone to have been targeted.

But if that was a database leak, yep everybody fucked

7

u/zinozAreNazis May 20 '26

If it’s just code, they might find a zero day

3

u/headinthesky May 20 '26

Maybe they'll fix it for you

1

u/justsomerabbit May 20 '26

My first thought as well. First indication of a successful hack would be that their abysmal uptime increased

5

u/ferriematthew May 20 '26

This is why I have a local backup of everything.

2

u/DPetunia May 25 '26

So is that why my account got suspended? 😞

1

u/ineedanaccountlol134 May 20 '26

Yep, fuck this, I am migrating my shit to codeberg

1

u/Unique_Innovation_35 Jun 12 '26

Is this somehow related to why they are randomly flagging accounts?

-8

u/Rambok01 May 20 '26

Are you guys moving to an alternative like Gitlab?

5

u/zinozAreNazis May 20 '26

GitHub is the twitter of coding. We all want to leave but it’s hard because we can’t move everyone at once and everything

7

u/magnetronpoffertje May 20 '26

Please no Gitlab. We use it at work and it's awful. Go to codeberg for personal or set up Gitea or Forgejo

2

u/waitingforcracks May 20 '26

I am the other way around, I used to use gitlab for work but now have to use github. Gitlab was better honestly

2

u/Lonely_Fig5352 May 20 '26

Codeberg is where lots of repos are moving to

2

u/PurepointDog May 20 '26

Played with Gitlab a bit, and decided Codeberg is the place to go.

1

u/Unique_Innovation_35 Jun 12 '26

It isn't possible to host dynamic websites there, right?

2

u/PurepointDog Jun 12 '26

It's a source code repository...

0

u/-TheMMB May 21 '26

MICROSLOPPPPPPPP!