A hacker group is poisoning open source code at an unprecedented scale
ID: a80004cb-0ec7-5009-9c11-fd8c03532929
STIX ID: report--a80004cb-0ec7-5009-9c11-fd8c03532929
Feed Name: Security - Ars Technica
Date Published: 2026-05-22
Date Updated: 2026-05-22
Author: Andy Greenberg and Lily Hay Newman, WIRED.com
A criminal group known as TeamPCP carried out a software supply-chain attack by distributing a poisoned VSCode extension that allowed them to access GitHub internals; GitHub confirmed around 3,800 compromised repositories and TeamPCP claims to be selling source code and internal org data. Socket reports the group has conducted roughly 20 waves of attacks, corrupting malware into over 500 distinct open-source projects, signaling a large, ongoing campaign of widespread supply-chain compromise and extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
