TeamPCP gained access to GitHub’s private source code after an employee unknowingly installed a malicious coding tool.