logo

A hacker group is poisoning open source code at an unprecedented scale

ID: a80004cb-0ec7-5009-9c11-fd8c03532929

STIX ID: report--a80004cb-0ec7-5009-9c11-fd8c03532929

Feed Name: Security - Ars Technica

Threat Score
88/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Andy Greenberg and Lily Hay Newman, WIRED.com

...
...

A criminal group known as TeamPCP carried out a software supply-chain attack by distributing a poisoned VSCode extension that allowed them to access GitHub internals; GitHub confirmed around 3,800 compromised repositories and TeamPCP claims to be selling source code and internal org data. Socket reports the group has conducted roughly 20 waves of attacks, corrupting malware into over 500 distinct open-source projects, signaling a large, ongoing campaign of widespread supply-chain compromise and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.