Microsoft disables over 70 GitHub repos after hackers compromised them with dangerous malware Some repos are already restored. TechRadar · Jun 9
Compromised Red Hat npm packages downloaded over 80,000 times in one week – supply chain attack still ongoing Security researchers spotted a new campaign using the same methods as TeamPCP. TechRadar · Jun 2
GitHub hit with another major attack — Megalodon hits over 5,000 repos with malware-laden commits A TeamPCP copycat was just spotted hitting thousands of GitHub repos with an infostealer. TechRadar · May 25
500 Poisoned Packages, Hundreds of Companies: TeamPCP's Worm Just Reached GitHub A GitHub employee installed a routine VS Code extension update, handed cybercrime group TeamPCP enough access to exfiltrate approximately 3,800 of GitHub's internal source code repositories — everything from platform infrastructure to proprietary tooling built by the company that hosts more than 420 million repositories for over 180 million developers… International Business Times · May 23
GitHub confirms breach — thousands of internal repositories hit after employee installs malicious VS Code extension TeamPCP continues its attack on open source projects, now apparently asking for $50,000. TechRadar · May 21
Mini Shai-Halud hackers publish over 600 compromised npm packages — developers warned to be on their guard The Shai-Hulud campaign continues, now affecting hundreds of new packages and potentially compromising thousands of projects. TechRadar · May 20
Hacker group hits 3,800 internal GitHub repositories via poisoned developer plugin — TeamPCP claims source code theft and attempts $50,000 sale, employee installed malicious VS Code extension GitHub has confirmed a breach involving roughly 3,800 internal repositories after an employee device was compromised through a malicious VS Code extension. The TeamPCP hacker group claims it stole internal source code and attempted to sell the data for at least $50,000. Tom’s Hardware · May 20
What is Mini Shai-Hulud npm supply chain attack, and was Microsoft and Socket hit by malware? Full explainer on npm malware spread What is Mini Shai-Hulud npm supply chain attack, and was Microsoft and Socket hit by malware? A new npm supply chain attack hit hundreds of packages linked to the @antv ecosystem. Attackers used a compromised maintainer account to publish malicious versions that stole credentials and spread across repositories. Microsoft and… The Economic Times · May 19
Hackers threaten to leak Mistral files online — AI giant confirms breach, but not what data is involved TeamPCP put the Mistral files up for sale, but if they're not sold in a week, they'll get leaked. TechRadar · May 15
OpenAI confirms security breach in TanStack supply chain attack, but says no user data was affected Two devices were compromised by TeamPCP's infostealing malware. TechRadar · May 15
EU cyberattack may have been worse than we thought - 90GB of data published online as 30 entities hit CERT-EU is blaming TeamPCP for the attack, saying the Trivy breach trickled down. TechRadar · Apr 3
Mercor, a $10 billion AI startup, confirms it was caught up in a major security incident Mercor confirmed it was hit by a supply-chain attack targeting LiteLLM, a widely used AI developer tool. Extortion gang Lapsus$ claims to have walked away with four terabytes of data. Fortune · Apr 2
Major compromise of the telnyx PyPI library could put millions of users at risk TeamPCP strikes again, with almost identical code to LiteLLM. TechRadar · Mar 30
CanisterWorm malware wipes Iranian machines for no apparent reason — sophisticated attack spreads through npm packages and uses ICP canister as control surface CanisterWorm malware wipes Iranian machines for no apparent reason Tom’s Hardware · Mar 26
TechRadar · Mar 25 Top LLM PyPl package compromised to steal user details - here's what we know Aqua Security’s Trivy vulnerability scanner compromise is trickling down into a hugely popular Python package.