News Grower

Independent coverage of AI, startups, and technology.

Ars Technica May 22, 2026 at 10:30 Big Tech Rising Hot

A hacker group is poisoning open source code at an unprecedented scale

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Andy Greenberg and Lily Hay Newman, WIRED.com Original source
A hacker group is poisoning open source code at an unprecedented scale

A so-called software supply chain attack, in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous foothold in a victim’s network. Now one group of cybercriminals has turned that occasional nightmare into a near-weekly episode, corrupting hundreds of open source tools, extorting victims for profit, and sowing a new level of distrust in an entire ecosystem used to create the world’s software. On Tuesday night, open source code platform GitHub announced that it had been breached by hackers in one such software supply chain attack: A GitHub developer had installed a “poisoned” extension for VSCode, a plug-in for a commonly used code editor that, like GitHub itself, is owned by Microsoft. As a result, the hackers behind the breach, an increasingly notorious group called TeamPCP, claim to have accessed around 4,000 of GitHub’s code repositories. GitHub’s statement confirmed that it had found at least 3,800 compromised repositories while noting that, based on its findings so far, they all contained GitHub’s own code, not that of customers. “We are here today to advertise GitHub’s source code and internal orgs for sale,” TeamPCP wrote on BreachForums, a forum and marketplace for cybercriminals. “Everything for the main platform is there and I very am happy to send samples to interested buyers to verify absolute authenticity.”Read full article Comments

Stay on the signal

Follow A hacker group is poisoning open source code at an unprecedented scale

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Carried, and Chain Attacks, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

May 22, 2026 at 16:24 Ars Technica

PSA: The Steam Controller’s magnetic charger can be a fire hazard

Keep the charging puck’s exposed pins far away from anything metal.

May 22, 2026 at 14:46 SecurityLab

Один пропущенный токен, репозитории GitHub и шантаж в духе Shai-Hulud. Хакеры взломали Grafana Labs

Grafana Labs раскрыла все детали взлома GitHub и объяснила, почему платить отказалась.

May 22, 2026 at 14:28 Ars Technica

NASA undertakes major reorganization to reduce bureaucracy and move faster

"It is imperative to concentrate resources towards the highest priority objectives."

May 22, 2026 at 11:30 Ars Technica

First vaccines, now mammograms? RFK Jr.’s latest firings have doctors outraged.

Doctors are angry and alarmed that preventive care could go the way of vaccines.

May 22, 2026 at 11:20 Ars Technica

Rocket Report: Starship launch delayed, German launch company may aid Canada

All eyes on South Texas for the latest Starship test flight.

May 22, 2026 at 10:30 Ars Technica

A hacker group is poisoning open source code at an unprecedented scale

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

2

Related articles

More stories that share tags, source, or category context.

SecurityLab May 22, 2026 at 14:46 Cybersecurity
Rising Hot

Один пропущенный токен, репозитории GitHub и шантаж в духе Shai-Hulud. Хакеры взломали Grafana Labs

Grafana Labs раскрыла все детали взлома GitHub и объяснила, почему платить отказалась.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page