Skip to main content

Share story

Security

TeamPCP hackers claim GitHub breach amid 20-wave supply chain attack spree

TeamPCP hackers claim GitHub breach amid 20-wave supply chain attack spree Image: primary
A group of cybercriminals known as TeamPCP has claimed responsibility for a breach of GitHub repositories through a poisoned VSCode extension. The attackers posted on BreachForums offering to sell access to around 4,000 of GitHub's code repositories. GitHub confirmed it found at least 3,800 compromised repositories containing its own code. Cybersecurity firm Socket reports that TeamPCP has executed 20 waves of supply chain attacks in recent months, compromising more than 500 pieces of software. The tainted code has allowed breaches at companies including OpenAI and data firm Mercor, according to Wiz threat intelligence lead Ben Read. The GitHub incident is the latest in the group's ongoing campaign targeting open source tools used by developers.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...

Policy AI
Policy AI

California subpoenas OpenAI over AI cybersecurity incidents

California's Department of Justice has subpoenaed OpenAI to obtain information about cybersecurity incidents involving its AI models and agents, Tom's Hardware reported. Attorney General Rob Bonta said the investigation seeks to d...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...