π¨ GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed
A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data.
The actor claims the dataset includes around 4,000 private repositories and says samples can be provided to interested buyers to verify authenticity.
ββββββββββββββββββββ
Target: GitHub
Country: United States
Sector: Technology / Software Development / Source Code
Incident Type: Alleged Source Code Sale
Claimed Exposure: Around 4,000 private repositories
Actor: TeamPCP
Price: Offers over $50,000
ββββββββββββββββββββ
According to the post, the actor claims the material includes source code and internal organization data tied to GitHubβs main platform. The post also references a public file list and includes screenshots showing numerous repository archive names.
Why it matters:
If authentic, exposed source code and internal repository data could increase the risk of code review by hostile actors, vulnerability discovery, supply chain targeting, impersonation, phishing, and follow-on attacks against developer infrastructure.
Status:
This remains an unverified underground forum claim. The actor states this is not a ransom attempt and claims the data may be leaked publicly if no buyer is found.
Stop guessing what's redacted. Subscribers see everything β https://t.co/281Qjc6WSh