HeadlinesBriefing favicon HeadlinesBriefing.com

TeamPCP breaches GitHub in supply chain attack, threatens open source trust

Ars Technica •
×

TeamPCP breached GitHub this week by compromising a developer's VSCode extension, gaining access to roughly 4,000 code repositories. The hackers posted the stolen source code and internal orgs for sale on BreachForums. GitHub confirmed at least 3,800 repositories were compromised, noting they contained only the company's own code, not customer data.

Over recent months, the group has executed 20 waves of supply chain attacks across more than 500 distinct pieces of software, targeting OpenAI, Mercor, and the European Commission. TeamPCP has automated its operations with a self-spreading worm dubbed Mini Shai-Hulud, which steals credentials to fuel a repeating cycle of compromise.

The GitHub breach follows a pattern of embedding malware in open source tools, then using stolen credentials to hijack other developer platforms. Hundreds of companies have fallen victim. The cycle repeats as each breached network feeds the next round of attacks, with no end in sight.