A coordinated hacker group known as TeamPCP has launched a large-scale poisoning campaign targeting open source code repositories, with GitHub being the latest platform compromised. The attacks represent an unprecedented wave of software supply chain compromises that could affect thousands of developers and applications relying on infected packages.
Why it matters: Supply chain attacks on open source code pose critical risks to any organization using third-party libraries, making this escalation a direct threat to software security practices across the tech and marketing technology industries.