Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    10 Statistical Traps We Often Overlook

    Man told ChatGPT he was feeling delusional. ChatGPT insisted he was Jesus.

    OpenAI’s secret model settles a $1M math problem

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI News»A hacker group is poisoning open source code at an unprecedented scale
    AI News

    A hacker group is poisoning open source code at an unprecedented scale

    By Updated:No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A hacker group is poisoning open source code at an unprecedented scale
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A so-called software supply chain attack, in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous foothold in a victim’s network. Now one group of cybercriminals has turned that occasional nightmare into a near-weekly episode, corrupting hundreds of open source tools, extorting victims for profit, and sowing a new level of distrust in an entire ecosystem used to create the world’s software.

    On Tuesday night, open source code platform GitHub announced that it had been breached by hackers in one such software supply chain attack: A GitHub developer had installed a “poisoned” extension for VSCode, a plug-in for a commonly used code editor that, like GitHub itself, is owned by Microsoft. As a result, the hackers behind the breach, an increasingly notorious group called TeamPCP, claim to have accessed around 4,000 of GitHub’s code repositories. GitHub’s statement confirmed that it had found at least 3,800 compromised repositories while noting that, based on its findings so far, they all contained GitHub’s own code, not that of customers.

    “We are here today to advertise GitHub’s source code and internal orgs for sale,” TeamPCP wrote on BreachForums, a forum and marketplace for cybercriminals. “Everything for the main platform is there and I very am happy to send samples to interested buyers to verify absolute authenticity.”

    The GitHub breach is just the latest incident in what has become the longest-running spree of software supply chain attacks ever, with no end in sight. According to cybersecurity firm Socket, which focuses on software supply chains, TeamPCP has, in just the last few months, carried out 20 “waves” of supply chain attacks that have hidden malware in more than 500 distinct pieces of software, or well over a thousand counting all of the various versions of the code that TeamPCP has hijacked.

    Code group Hacker open poisoning Scale source unprecedented
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle I/O showed how the path for AI-driven science is shifting
    Next Article Rocket Report: Starship launch delayed, German launch company may aid Canada
    • Website

    Related Posts

    AI News

    Nuclear startup Bluecore Energy raises $50M seed round, just two months after launch

    AI News

    The White House made a “Tetris” clone. The Tetris Company was not amused.

    Chatbots

    A hacker stole $340M in a crypto heist, then returned most of it

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Statistical Traps We Often Overlook

    0 Views

    Man told ChatGPT he was feeling delusional. ChatGPT insisted he was Jesus.

    0 Views

    OpenAI’s secret model settles a $1M math problem

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10 Statistical Traps We Often Overlook

    0 Views

    Man told ChatGPT he was feeling delusional. ChatGPT insisted he was Jesus.

    0 Views

    OpenAI’s secret model settles a $1M math problem

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.