GitHub investigates internal repositories breach claimed by TeamPCP

2026-05-20T07:23:26Zdf706802e6f1378cc790b3eda18cee258891830e15a89eb12bb94c5c41db038d
7-eleven-breachazure-sspr-abusechromadbcode-signing-abusediscord-e2eefastapigithub-breachinterpol-operation-ramzmacos-infostealermalware-signing-as-a-servicemicrosoft-artifact-signingnpm-supply-chainprivate-repositoriesrceremote-code-executionsecurity-patchingshai-huludshinyhuntersteampcpwindows-update-issues

What happened

Multiple high-impact security incidents and vulnerabilities were reported: GitHub is investigating an alleged breach of ~4,000 internal/private repositories claimed by TeamPCP; a "max-severity" RCE in the FastAPI Python build of ChromaDB can allow unauthenticated server-side code execution; Microsoft disrupted a malware-signing-as-a-service that abused its Artifact Signing platform to produce fraudulent code-signing artifacts; and a new Shai-Hulud supply-chain wave published >600 malicious npm packages. Other notable items include abuse of Microsoft Self-Service Password Reset (SSPR) in Azure/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
df706802e6f1378cc790b3eda18cee258891830e15a89eb12bb94c5c41db038d
Enrichment time
2026-05-20T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.