logo

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

ID: ece81f3e-1bb3-538f-9352-cb378eebde50

STIX ID: report--ece81f3e-1bb3-538f-9352-cb378eebde50

Feed Name: WIRED Security

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Andy Greenberg, Lily Hay Newman

...
...

A criminal group named TeamPCP has carried out an extensive, ongoing software supply-chain campaign: by compromising developer tools (for example a poisoned VSCode extension) and deploying a self-spreading worm (Mini Shai-Hulud) the group has injected malware into hundreds of open-source projects, stolen credentials to push further malicious updates, and claims to have accessed roughly 3,800 GitHub repositories—using the access for extortion and to advertise stolen source code for sale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.