A hacker group is poisoning open source code at an unprecedented scale

A hacker group is poisoning open source code at an unprecedented scale

A significant escalation in software supply chain attacks has emerged, with cybercriminals compromising trustworthy software to embed their malicious codes. Once considered infrequent, these attacks have now become alarmingly routine, creating a chilling atmosphere of insecurity in the open source community. Recently, GitHub announced a security breach linked to one such attack. A developer unknowingly installed a compromised extension for Visual Studio Code (VSCode), a widely used code editor developed by Microsoft. This incident is attributed to the cybercrime group TeamPCP, which claims to have infiltrated approximately 4,000 GitHub repositories through this breach. GitHub confirmed that at least 3,800 of these repositories were indeed compromised, revealing that they contained GitHub's proprietary code rather than that of its users. In a shocking statement on BreachForums, a notorious marketplace for cybercriminals, TeamPCP declared their intentions to auction GitHub's source code and internal structures, offering samples to potential buyers to prove authenticity. This breach represents the latest chapter in an ongoing saga of software supply chain attacks that have reached unprecedented levels of frequency and severity. According to cybersecurity experts at Socket, TeamPCP has executed 20 distinct waves of attacks in recent months, embedding malware into over 500 different software packages. The ongoing nature of these attacks raises significant concerns about the integrity of software development and the trustworthiness of open source tools that are foundational to modern software creation.

Sources : Ars Technica

Published On : May 22, 2026, 10:35

Automotive
Waymo Faces Challenges with Autonomous Ride Services Amid Flooding Issues

Waymo has encountered a turbulent month as it has temporarily halted rider services across six cities and suspended high...

Business Insider | May 25, 2026, 08:40
Waymo Faces Challenges with Autonomous Ride Services Amid Flooding Issues
AI
Apple Poised for AI Breakthrough Ahead of WWDC 2026 with New Generative AI Focus

As anticipation builds for the upcoming World Wide Developers Conference (WWDC) 2026, Apple has piqued interest with the...

Business Today | May 25, 2026, 05:15
Apple Poised for AI Breakthrough Ahead of WWDC 2026 with New Generative AI Focus
AI
AI-Powered Wedding Planning Takes a Unique Twist with Viral Emoji Reveal

Austin Lau, a marketing professional at Anthropic, has pioneered a novel approach to wedding planning using AI technolog...

Business Insider | May 25, 2026, 09:35
AI-Powered Wedding Planning Takes a Unique Twist with Viral Emoji Reveal
Gadgets
Beat the Heat: Sony Unveils Innovative Wearable Air Conditioner

Sony has introduced an innovative wearable air conditioning device known as the Reon Pocket Pro Plus, designed to assist...

Business Today | May 25, 2026, 07:55
Beat the Heat: Sony Unveils Innovative Wearable Air Conditioner
AI
Decoding the AI Lexicon: Essential Terms to Understand the Revolution

The artificial intelligence landscape has exploded in recent years, making it nearly impossible to overlook its presence...

Business Insider | May 25, 2026, 09:50
Decoding the AI Lexicon: Essential Terms to Understand the Revolution
View All News