AUTO-UPDATED

The sandworm malware strikes: How a hacker group stole 4,000 GitHub repositories and exposed the rot at the core of modern software security

The hacker group TeamPCP has compromised 4,000 private GitHub repositories after infiltrating software supply chains through poisoned development tools, including VS Code extensions and trusted security scanners.

Key Points

  • TeamPCP is selling 4,000 stolen GitHub repositories for $50,000 after gaining access via a malicious VS Code extension.
  • The group previously compromised the Trivy security scanner, allowing them to steal AWS keys, SSH credentials, and Kubernetes tokens from over 10,000 workflows.
  • Attackers successfully breached Cisco Systems, cloning 300 repositories containing source code for unreleased AI products and sensitive data from government and banking clients.
  • Malicious code propagated through the Bitwarden password manager and TanStack library by hijacking legitimate build pipelines and valid cryptographic signatures.
  • The malware specifically targets AI assistant credentials, including those for Claude Code, marking a new trend in supply chain exploitation.

Why it Matters

This breach exposes a systemic failure in the software industry's reliance on automated build tools and implicit trust in third-party development packages. Because the attackers use valid digital signatures to sign malicious code, traditional security verification tools are currently unable to distinguish between legitimate and compromised software updates.
Naturalnews.com Published by Patrick Lewis
Read original