A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
Source: Wired Security · Category: Supply Chain
TeamPCP gang carried out unprecedented supply chain attack on open-source code, compromising hundreds of organizations via GitHub and multiple repositories. Corroborates articles [0], [5], [14] on npm/GitHub poisoning. Law firm dependencies on open-source libraries face heightened contamination risk. Urgent: audit and lock open-source package versions.