Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124


What is called software Supply chain attackthe way hackers destroy legitimate software to hide their malicious code, was once uncommon but has plagued the world of cyber security with the stealthy threat of turning any innocent software into a dangerous place on the victim’s Internet. Now one group of cyber criminals has turned these occasional horrors into weekly events, destroying hundreds of open-source devices, extorting victims for profit, and sowing a new level of distrust in the entire world of programming.
On Tuesday night, the open source platform GitHub announced that it was breached by hackers in such an attack: The developer of GitHub installed a “poisonous” extension of VSCode, a plug-in for the editor of widely used code which, like GitHub itself, belongs to Microsoft. As a result, the hackers who breached the law, an increasingly popular group known as TeamPCP, have reportedly accessed nearly 4,000 GitHub repositories. GitHub’s statement confirmed that it had found at least 3,800 repositories when it determined that, based on what it had found so far, they all contained GitHub’s code, not the customer’s.
“We are here today to promote GitHub sources and internal vendor orgs,” TeamPCP posted on BreachForums, a forum and marketplace for cybercriminals. “Everything for the main platform is available and I am happy to send samples to interested buyers to confirm the authenticity.”
The GitHub breach is the latest in a long-running, never-ending series of software attacks. According to the cybersecurity company Socket, which focuses on software chains, TeamPCP, in the past few months, has carried out 20 “waves” of attacks that have hidden malware in more than 500 programs, or more than a thousand to count all the different types of code that TeamPCP has stolen.