The hacker group TeamPCP has compromised 4,000 private GitHub repositories after infiltrating software supply chains through poisoned development tools, including VS Code extensions and trusted security scanners.
Key Points
- TeamPCP is selling 4,000 stolen GitHub repositories for $50,000 after gaining access via a malicious VS Code extension.
- The group previously compromised the Trivy security scanner, allowing them to steal AWS keys, SSH credentials, and Kubernetes tokens from over 10,000 workflows.
- Attackers successfully breached Cisco Systems, cloning 300 repositories containing source code for unreleased AI products and sensitive data from government and banking clients.
- Malicious code propagated through the Bitwarden password manager and TanStack library by hijacking legitimate build pipelines and valid cryptographic signatures.
- The malware specifically targets AI assistant credentials, including those for Claude Code, marking a new trend in supply chain exploitation.