Hacker Group Conducts Large-Scale Supply Chain Attacks on Open Source Code
TeamPCP has carried out extensive software supply chain attacks affecting hundreds of organizations through compromised open source repositories.

A hacker group known as TeamPCP has been conducting software supply chain attacks at an unprecedented scale, targeting open source code repositories and affecting hundreds of organizations, according to security researchers.
The group has been systematically compromising software packages in open source repositories, inserting malicious code that can then be distributed to downstream users and organizations that rely on these packages. GitHub is among the platforms that have been targeted in these attacks.
Software supply chain attacks have become an increasingly serious cybersecurity threat, as they allow attackers to compromise multiple targets by poisoning widely-used code libraries and packages. When organizations download and use these compromised packages, they unknowingly introduce malicious code into their own systems.
The scale of TeamPCP's operations appears to be significantly larger than previous supply chain attack campaigns, with security experts describing the scope as unprecedented. The attacks highlight the vulnerabilities inherent in the open source software ecosystem, where code packages are often developed and maintained by volunteers with limited security oversight.
Organizations that use open source software components are advised to implement additional security measures to verify the integrity of packages before incorporating them into their systems. The attacks underscore the need for improved security practices across the software supply chain.