By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Destiny 3 Is Not Happening as Bungie Plans Layoffs

Destiny 3 Is Not Happening as Bungie Plans Layoffs

News Room News Room 22 May 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
News

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

News Room
Last updated: 22 May 2026 04:46
By News Room 5 Min Read
Share
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
SHARE

A so-called software supply chain attack, in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous foothold in a victim’s network. Now one group of cybercriminals has turned that occasional nightmare into a near-weekly episode, corrupting hundreds of open source tools, extorting victims for profit, and sowing a new level of distrust in an entire ecosystem used to create the world’s software.

On Tuesday night, open source code platform GitHub announced that it had been breached by hackers in one such software supply chain attack: A GitHub developer had installed a “poisoned” extension for VSCode, a plug-in for a commonly used code editor that, like GitHub itself, is owned by Microsoft. As a result, the hackers behind the breach, an increasingly notorious group called TeamPCP, claim to have accessed around 4,000 of GitHub’s code repositories. GitHub’s statement confirmed that it had found at least 3,800 compromised repositories while noting that, based on its findings so far, they all contained GitHub’s own code, not that of customers.

“We are here today to advertise GitHub’s source code and internal orgs for sale,” TeamPCP wrote on BreachForums, a forum and marketplace for cybercriminals. “Everything for the main platform is there and I very am happy to send samples to interested buyers to verify absolute authenticity.”

The GitHub breach is just the latest incident in what has become the longest-running spree of software supply chain attacks ever, with no end in sight. According to cybersecurity firm Socket, which focuses on software supply chains, TeamPCP has, in just the last few months, carried out 20 “waves” of supply chain attacks that have hidden malware in more than 500 distinct pieces of software, or well over a thousand counting all of the various versions of the code that TeamPCP has hijacked.

Those tainted pieces of code have allowed TeamPCP’s hackers to breach hundreds of companies that installed the software, says Ben Read, who leads strategic threat intelligence at the cloud security firm Wiz. GitHub is only the latest on the group’s long list of victims, which has also included AI firm OpenAI and the data contracting firm Mercor. “It may be their biggest one,” Read says of the GitHub breach. “But each one of these is a big deal for the company that it happens to. It’s not qualitatively different from the 14 breaches that happened last week.”

TeamPCP’s core tactic has become a kind of cyclical exploitation of software developers: The hackers gain access to a network where an open source tool commonly used by coders is being developed—for example, the VSCode extension that led to the GitHub breach or the data visualization software AntV that TeamPCP hijacked earlier this week. The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders.

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows. “It’s a flywheel of supply chain compromises,” says Read. “It’s self-perpetuating, and it’s been a hugely successful way to get access to networks and steal stuff.”

Most recently, the group appears to have automated many of its software supply chain attacks with a self-spreading worm that’s come to be known as Mini Shai-Hulud. The name comes from GitHub repositories the worm creates that include encrypted credentials stolen from victims, each of which includes the phrase “A Mini Shai-Hulud Has Appeared” along with a handful of other references to the sci-fi novel Dune. That message in turn appears to be a reference not just to Dune’s sandworms but to a similar supply chain compromise worm known as Shai-Hulud that appeared in September, though there’s no evidence TeamPCP was behind that earlier self-spreading malware.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The Department of Labor’s Faith Leader Is Now Also in Charge of Its Civil Rights Enforcement

The Department of Labor’s Faith Leader Is Now Also in Charge of Its Civil Rights Enforcement

News Room News Room 22 May 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

The Endless guitar pedal lets you use AI to roll your own effects

I’m not sure anyone was really asking for an AI guitar pedal. But it was…

22 May 2026

The Best Yoga Mats

Designed for yoga, Pilates, strength training and any exercise that involves light movement, the Play…

22 May 2026

Anker’s new earbuds are the first with its AI chip that boosts noise reduction

The Liberty 5 Pro are available starting today for $169.99 in blue, white, black, and…

22 May 2026
Gaming

Space Marine 2 for PC Drops to $17.99 (or Less)

Space Marine 2 for PC Drops to .99 (or Less)

Legionnaires rejoice, Warhammer 40,000: Space Marine 2, one of the best games of 2024, has dropped to an incredible low price fresh off the heels of Warhammer Skulls 2026. From…

News Room 22 May 2026

Your may also like!

Destiny 2 Fans React to Bungie Ending Support for the Game
Gaming

Destiny 2 Fans React to Bungie Ending Support for the Game

News Room 22 May 2026
Can OpenAI’s ‘Master of Disaster’ Fix AI’s Reputation Crisis?
News

Can OpenAI’s ‘Master of Disaster’ Fix AI’s Reputation Crisis?

News Room 22 May 2026
Anker’s new earbuds have the best call quality I’ve ever heard
News

Anker’s new earbuds have the best call quality I’ve ever heard

News Room 22 May 2026
Take-Two Boss on GTA 6 Trailer 3 Talk
Gaming

Take-Two Boss on GTA 6 Trailer 3 Talk

News Room 22 May 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?