A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

Source: Wired Security  ·  Category: Supply Chain


TeamPCP gang carried out unprecedented supply chain attack on open-source code, compromising hundreds of organizations via GitHub and multiple repositories. Corroborates articles [0], [5], [14] on npm/GitHub poisoning. Law firm dependencies on open-source libraries face heightened contamination risk. Urgent: audit and lock open-source package versions.

→ Read the full article

Read more