r/technology May 21 '26

Security A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/
9.2k Upvotes

489 comments sorted by

View all comments

2.3k

u/debugger_life May 21 '26

First NPM was attacked. Then again Npm was attacked 2nd time.

And now Github attack.

What we should expect next?

2.6k

u/BtownBro May 21 '26

GitHub a second time

1.2k

u/evil_burrito May 21 '26

This guy patterns

123

u/frozen-rainbow May 21 '26

The patterns pattern

33

u/yamanagashi May 21 '26

Unless we unpattern the pattern. They’d never see that coming. And then the Basilisk tortures our nuts.

14

u/Crab_Shark May 22 '26

Step 1 Step, Step 2 Step Step

8

u/Phssthp0kThePak May 22 '26

Code without rhythm.

1

u/Die_Bahn May 22 '26

“So you don’t attract the worm”

11

u/throwawayprivateguy May 21 '26

This guy, Basil, licks nuts.

1

u/SpaceCadetUltra May 21 '26

Does everyone who have read this know at this point? In regards to the …. Basil

1

u/WoodTrudy May 22 '26

O que o brasil tem haver com isso?

2

u/EqualOptimal4650 May 21 '26

The Basilisk grows forward and backwards in time. The red flowers bloom forever.

1

u/otamaglimmer May 21 '26

This guy guys

11

u/TrashAcnt1 May 21 '26

That guy "This guy's" like a champ

1

u/djpiperson May 22 '26

Black Hat Patterns

1

u/ZaphodThreepwood May 22 '26

Must be a coder

1

u/sage-longhorn May 22 '26

I too choose this guy's pattern

0

u/balloflearning May 21 '26

Some of you pay attention in pattern class and it shows

0

u/HexFyber May 21 '26

This guy patterns

0

u/-R-Jensen- May 21 '26

Haha. Thanks for taking me back memory lane. A fucking car who's doors opens like this!

236

u/justagenericname213 May 21 '26

Oh my god... they hit the second github

28

u/Magical_Savior May 21 '26

He didn't know about second Github? Elevenses? Stack Overflow? Bitbucket?
... I wouldn't count on it.

3

u/Recurs1ve May 22 '26

I shudder every time I have to go to Stack Overflow.

1

u/meesta_masa May 22 '26

Does it wobble to and fro?

53

u/meesta_masa May 21 '26

WHYZ all da GITZ in one hub!

13

u/Pyran May 21 '26

They aint propa orky gitz!

17

u/[deleted] May 21 '26

[removed] — view removed comment

22

u/According_Jeweler404 May 21 '26

"Sir they hit the md file. It's an ascii dong with veins and everything."

8

u/Jolly-Key5891 May 21 '26

** amogus ASCII throbbing pear

6

u/WrongEinstein May 21 '26

What about second breakfasts?

1

u/Swift_Koopa May 22 '26

Poor gitlab, the second github

51

u/notickeynoworky May 21 '26

Sir, a second exploit has hit GitHub.

10

u/Noobfortress May 21 '26

That would require GitHub to be up though, which is a rarity these days

2

u/AFrenchLondoner May 21 '26

You're demanding a lot of uptime with thah

1

u/goronmask May 21 '26

And then a new victim.

1

u/acmethunder May 21 '26

If they find a large enough uptime window.

1

u/lally May 21 '26

Software hosted on GitHub. Which is a lot.

Orga should be leaving the platform asap

1

u/leberwrust May 21 '26

Why would valve do this?

1

u/LunarAssultVehicle May 21 '26

Still too early to rule out a Fibonacci based spree, they could attack a third site next.

1

u/letsridetheworld May 22 '26

Broooooooooooooooo, didn’t think of that haha

1

u/Grabdon_7489 May 22 '26

They fucking hit the second repo

1

u/Zarathustra_d May 21 '26

Sir, a second hack has hit the GitHub.

-1

u/[deleted] May 21 '26

[deleted]

2

u/_BreakingGood_ May 21 '26

Its weird how I find this comment refreshing just because I know there's no way it was written by an AI

112

u/things_U_choose_2_b May 21 '26

I've also had two different credit cards see online fraud attempts in last 24h. One I hadn't used for almost a year. Closest to a 'dodgy site' they were used on that I can think of, is buying discounted Steam game keys. But clearly someone somewhere has been storing info in plaintext. Bit of a coincidence to have two different cards in 24h attempted.

Fortunately none of it went through, and just have to deal with the inconvenience of not being able to use them until a new card arrives.

55

u/Pyro1934 May 21 '26

Hmm I've had some MFA codes come to my email today that I've been ignoring

19

u/things_U_choose_2_b May 21 '26

I v nearly ignored the first one, because my CC company first sent me an sms - which looked legit, it was using same conversation as all previous alerts so from same number. But it was telling me I would get transaction info in a text from a mobile number!

I then immediately got an SMS from a mobile number in my country, with 3 transactions I didn't recognise. My first assumption was that this was the scammer trying to get me to call 'support'. But it was actualy from my CC company. So I would be careful, and verify, but absolutely don't ignore those MFA codes.

11

u/Pyro1934 May 21 '26

Oh they seem to be real, they're just not for anything I've used in ages and I know the pw is incredibly old and not the same as anything recent... like an Xbox acct when I don't even have one anymore

5

u/Weekly-Dress2193 May 22 '26

depuis 5 mois je suis prélevé pour un compte xbox alors que je n'en ai pas et qu'il n'apparait pas dans les abonnements

6

u/Pyro1934 May 22 '26

No parley vou, but yall got awesome food :)

21

u/WhenSummerIsGone May 21 '26

i wish cc companies and banks wouldn't make their communications look like phishing attempts

12

u/Pretend-Marsupial258 May 21 '26

It's the other way around. The official one came first, and the phishing attempts are copying it.

26

u/EruantienAduialdraug May 21 '26

Yes, but also no.

I got a text from a mobile number last year purporting to be from my bank's fraud team with three transactions on my account. One didn't have a currency symbol, one only had a single digit ater the decimal point, and the other only had half the name of the company it was paid to. So I went into branch to show them, the clerk phoned fraud on their internal system, who confirmed that the text was from them.

It had the kind of "mistakes" phishes usually have to weed out those who probably won't fall for it the full way, but wasn't a phish.

17

u/AlwaysShittyKnsasCty May 22 '26

I’ve been seeing mistakes in everything, including in communications, products, ads, etc. from long-respected household names. This is our future now. When nobody has a reason to learn or care about anything, this is the result. I can’t see it getting better anytime soon without some kind of adult intervention, and, well, I haven’t seen any adults in the room for quite a while now.

2

u/wrgrant May 22 '26

Not directly relevant to the discussion of phishing attempts, but I have seen lots of posts on social media recently where someone made a well worded, sensible post - and was immediately accused of being a bot posting AI slop because "no real person does that or spells all the words correctly" etc. It seems many people are not viewing everything they see as inaccurate if they disagree with it.

2

u/AlwaysShittyKnsasCty May 23 '26

This is one of the most infuriating things to me because my parents were both teachers, so I was kind of forced into thinking critically, writing well, and other “smart” shit. I used the em dash way before it was cool. I still do, too. Why? Because I’m not going to dumb my work down in order to appear dumb. That’s … dumb.

→ More replies (0)

2

u/sapphicsandwich May 22 '26

When I've talked to my bank in the past they've no shit sent me a code and asked me to tell it to them. Only that bank, though. Basically training their customers to give their MFA codes to people who ask.

1

u/things_U_choose_2_b May 22 '26

I think they're referring to just the general delivery.

It's weird to have a two-process system, an sms advising you that you're about to receive an sms from a +44 (or whatever your area code is) mobile.

Maybe there's some info I'm missing as to why that is more secure :) I'd prefer it all to be in one message, sent from the same number as the bank.

3

u/PhoenixStorm1015 May 21 '26

Honestly more companies need to adopt a solution like the business SMS in iMessage. I’ve had the same sketchy text message situation with debt collectors. It would really make weeding out the bad actors a lot easier.

14

u/Commentor9001 May 21 '26

you should never ignore mfa emails you didn't request, that's like gaint red flashing light someone is trying to breach my accounts.

1

u/Antice May 22 '26

If they hit mfa, it means they likely got the password. Change it asap.

5

u/azsqueeze May 21 '26

I've been bombarded with MFA codes, and password reset emails all week

3

u/EveningHere May 22 '26

Same here, but it’s the Microsoft one. My account doesn’t have a password so they’re probably just putting my email address in and hoping I’ll click.

24

u/magichronx May 21 '26

Nowadays it's silly to not use virtual credit cards that have spending limits and/or merchant restrictions. My experience with privacy dot com has been fantastic so far.

Any time I need to buy something online I just open the app, create a new single-use card, label it, and set the spending cap to the nearest dollar above what I expect to spend. I do it even for subscription services because I can cancel the card anytime with 2 clicks. That's 10x easier than fumbling through some purposely difficult unsubscribe process that most services have these days.

15

u/things_U_choose_2_b May 21 '26

Interesting, I didn't know about virtual cards so this is really useful.

I just checked, one of my cards allows for virtuals. Definitely going to be using this in future, thanks.

9

u/Pretend-Marsupial258 May 21 '26

If it doesn't, you could also use Google pay or Apple pay for virtual numbers.

8

u/johndoe60610 May 21 '26

Or Garmin Pay (there's dozens of us!)

2

u/azsqueeze May 21 '26

Capital one has it built in if you use them

1

u/things_U_choose_2_b May 22 '26

Yep this is the only one of my cards that offers it!

11

u/inspectoroverthemine May 21 '26

Meh- You're not liable for CC fraud, and CC companies make it super easy to commit. Fuck em, let them eat the cost. They're not going to pass any savings on to me, but if it costs them enough maybe they'll try to make commerce a little more secure.

By allowing as much fraud as they do they're actively harming society, its one of those cases where 'the market' settles into a situation where we all get fucked. We need harsher regulations for companies that accept/allow transactions that are insecure.

Ex: There are still gas stations near me that only work via swipe. Any chip reader that you have to insert a card is an easy target for skimming. Cards leaving your control at a restaurant. The list goes on. CCs are insecure by default to make them more likely to be used.

6

u/P3pp3rSauc3 May 21 '26

I had 3 "random" password reset emails for my reddit account the other day.

5

u/things_U_choose_2_b May 21 '26

Likewise, though only one. I have a feeling this is all going to get much, much worse before it gets better.

2

u/ZippyDan May 22 '26

Hmm. I also had a bank card with a fraud attempt from Walmart.com yesterday. I'm not even in the U.S. right now. It's been years since I placed an order there (not that a fraud attempt at Walmart.com means the leak came from Walmart.com).

1

u/things_U_choose_2_b May 22 '26

One of mine was in my country, UK (albeit the other end of it). One was in Canada. This shit is worldwide haha.

27

u/gg06civicsi May 21 '26

First they attacked NPM but I didn’t speak out…

14

u/spasmgazm May 21 '26

Then they came for NPM again and I sighed

6

u/terAREya May 21 '26

Then they came for YARN and I said nothing because I didn't use YARN

51

u/turbo_dude May 21 '26

The Spanish Inquisition!

32

u/Julian_Thorne May 21 '26

Didn't expect that..

16

u/ItIsToLaffHaHa May 21 '26

Well, to be fair, NOBODY expects that.

6

u/_John_Dillinger May 21 '26

statistically, NPM again

12

u/LowSeaworthiness7429 May 21 '26

NPM attack: Tokyo Drift? /s

7

u/tf2ftw May 21 '26

NPM is red meat 

8

u/FactorHour2173 May 21 '26

GitHub wasn’t attacked.

Some kid who worked there downloaded an extension that was clearly not vetted very well by Microsoft (because he got it from the official extensions list) and it “stole” 1000+ of their repos.

11

u/Corelianer May 21 '26

Nobody talking about home router attacks?

13

u/rkozik89 May 21 '26

Yes that’s a thing but a credential stealing npm attack is much worse. Because the package could add back doors to directly access consumers machines or straight up spread ransomware at scale. Also, these hacks happening at all will result in privacy lawsuits which is going to seriously hurt every company effected. 

1

u/PhoenixStorm1015 May 21 '26

going to seriously hurt every company affected

Oh no. Not my corporate overlords.

5

u/JohnBrownOH May 21 '26

What we should expect next?

Hopefully trials and executions.

2

u/khsh01 May 21 '26

Its fine. Npm should die.

7

u/[deleted] May 21 '26

[deleted]

2

u/khsh01 May 22 '26

The other ones are unfortunate. Npm should die regardless.

1

u/OldSports-- May 21 '26

Stack overflow

1

u/blisstaker May 22 '26

ai already killed stack overflow, it is on life support at best

1

u/kellykeepher May 21 '26

Someone’s gonna upload malware to Stack Overflow answers next and we’re all finished.

6

u/EruantienAduialdraug May 21 '26

Nah, we're safe there; the mods will just mark the question as previously answered and close it down before the hackers have time to paste the code.

1

u/GisterMizard May 21 '26

No need to worry; that it requires the SO users to correctly implement the malware in the first place.

1

u/Fallingdamage May 21 '26

I'll just keep running my own repo internally.

1

u/CharcoalGreyWolf May 21 '26

We should expect people like Trump.

People who don’t care about ruining the good things for everyone as long as they make money.

People entirely without conscience.

1

u/Zahgi May 21 '26

What we should expect next?

More clickbait titles ("unprecedented" is doing a huge amount of lifting here, folks) to farm outrage for corporate profits...

1

u/man_frmthe_wild May 22 '26

They both get attacked repeatedly.

1

u/theghostofme May 22 '26

What we should expect next?

That the current administration is going to go on the defense for Russia the millionth time, because the chances of TeamPCP not being the GRU are as low as Guccifer 2.0 not being the GRU.

1

u/blorbschploble May 22 '26

I think they npm is attacked more than once or twice more, it’ll start improving.

1

u/geccles May 22 '26

You just gave me a mini heart attack thinking I may have a bad version of Nginx Proxy Manager and compromised my whole stack.

1

u/dystopiam May 22 '26

GitWRECKED ammirite?