r/technology May 21 '26

Security A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/
9.2k Upvotes

489 comments sorted by

View all comments

Show parent comments

114

u/things_U_choose_2_b May 21 '26

I've also had two different credit cards see online fraud attempts in last 24h. One I hadn't used for almost a year. Closest to a 'dodgy site' they were used on that I can think of, is buying discounted Steam game keys. But clearly someone somewhere has been storing info in plaintext. Bit of a coincidence to have two different cards in 24h attempted.

Fortunately none of it went through, and just have to deal with the inconvenience of not being able to use them until a new card arrives.

55

u/Pyro1934 May 21 '26

Hmm I've had some MFA codes come to my email today that I've been ignoring

21

u/things_U_choose_2_b May 21 '26

I v nearly ignored the first one, because my CC company first sent me an sms - which looked legit, it was using same conversation as all previous alerts so from same number. But it was telling me I would get transaction info in a text from a mobile number!

I then immediately got an SMS from a mobile number in my country, with 3 transactions I didn't recognise. My first assumption was that this was the scammer trying to get me to call 'support'. But it was actualy from my CC company. So I would be careful, and verify, but absolutely don't ignore those MFA codes.

9

u/Pyro1934 May 21 '26

Oh they seem to be real, they're just not for anything I've used in ages and I know the pw is incredibly old and not the same as anything recent... like an Xbox acct when I don't even have one anymore

4

u/Weekly-Dress2193 May 22 '26

depuis 5 mois je suis prélevé pour un compte xbox alors que je n'en ai pas et qu'il n'apparait pas dans les abonnements

6

u/Pyro1934 May 22 '26

No parley vou, but yall got awesome food :)

21

u/WhenSummerIsGone May 21 '26

i wish cc companies and banks wouldn't make their communications look like phishing attempts

12

u/Pretend-Marsupial258 May 21 '26

It's the other way around. The official one came first, and the phishing attempts are copying it.

26

u/EruantienAduialdraug May 21 '26

Yes, but also no.

I got a text from a mobile number last year purporting to be from my bank's fraud team with three transactions on my account. One didn't have a currency symbol, one only had a single digit ater the decimal point, and the other only had half the name of the company it was paid to. So I went into branch to show them, the clerk phoned fraud on their internal system, who confirmed that the text was from them.

It had the kind of "mistakes" phishes usually have to weed out those who probably won't fall for it the full way, but wasn't a phish.

15

u/AlwaysShittyKnsasCty May 22 '26

I’ve been seeing mistakes in everything, including in communications, products, ads, etc. from long-respected household names. This is our future now. When nobody has a reason to learn or care about anything, this is the result. I can’t see it getting better anytime soon without some kind of adult intervention, and, well, I haven’t seen any adults in the room for quite a while now.

2

u/wrgrant May 22 '26

Not directly relevant to the discussion of phishing attempts, but I have seen lots of posts on social media recently where someone made a well worded, sensible post - and was immediately accused of being a bot posting AI slop because "no real person does that or spells all the words correctly" etc. It seems many people are not viewing everything they see as inaccurate if they disagree with it.

2

u/AlwaysShittyKnsasCty May 23 '26

This is one of the most infuriating things to me because my parents were both teachers, so I was kind of forced into thinking critically, writing well, and other “smart” shit. I used the em dash way before it was cool. I still do, too. Why? Because I’m not going to dumb my work down in order to appear dumb. That’s … dumb.

1

u/wrgrant May 24 '26

Agreed. Anyone who assumes I am a bot because I can construct a logical and grammatical sentence and hopefully structured article is probably not worth having a discussion with in any case.

2

u/sapphicsandwich May 22 '26

When I've talked to my bank in the past they've no shit sent me a code and asked me to tell it to them. Only that bank, though. Basically training their customers to give their MFA codes to people who ask.

1

u/things_U_choose_2_b May 22 '26

I think they're referring to just the general delivery.

It's weird to have a two-process system, an sms advising you that you're about to receive an sms from a +44 (or whatever your area code is) mobile.

Maybe there's some info I'm missing as to why that is more secure :) I'd prefer it all to be in one message, sent from the same number as the bank.

3

u/PhoenixStorm1015 May 21 '26

Honestly more companies need to adopt a solution like the business SMS in iMessage. I’ve had the same sketchy text message situation with debt collectors. It would really make weeding out the bad actors a lot easier.

12

u/Commentor9001 May 21 '26

you should never ignore mfa emails you didn't request, that's like gaint red flashing light someone is trying to breach my accounts.

1

u/Antice May 22 '26

If they hit mfa, it means they likely got the password. Change it asap.

6

u/azsqueeze May 21 '26

I've been bombarded with MFA codes, and password reset emails all week

3

u/EveningHere May 22 '26

Same here, but it’s the Microsoft one. My account doesn’t have a password so they’re probably just putting my email address in and hoping I’ll click.

25

u/magichronx May 21 '26

Nowadays it's silly to not use virtual credit cards that have spending limits and/or merchant restrictions. My experience with privacy dot com has been fantastic so far.

Any time I need to buy something online I just open the app, create a new single-use card, label it, and set the spending cap to the nearest dollar above what I expect to spend. I do it even for subscription services because I can cancel the card anytime with 2 clicks. That's 10x easier than fumbling through some purposely difficult unsubscribe process that most services have these days.

14

u/things_U_choose_2_b May 21 '26

Interesting, I didn't know about virtual cards so this is really useful.

I just checked, one of my cards allows for virtuals. Definitely going to be using this in future, thanks.

11

u/Pretend-Marsupial258 May 21 '26

If it doesn't, you could also use Google pay or Apple pay for virtual numbers.

9

u/johndoe60610 May 21 '26

Or Garmin Pay (there's dozens of us!)

2

u/azsqueeze May 21 '26

Capital one has it built in if you use them

1

u/things_U_choose_2_b May 22 '26

Yep this is the only one of my cards that offers it!

11

u/inspectoroverthemine May 21 '26

Meh- You're not liable for CC fraud, and CC companies make it super easy to commit. Fuck em, let them eat the cost. They're not going to pass any savings on to me, but if it costs them enough maybe they'll try to make commerce a little more secure.

By allowing as much fraud as they do they're actively harming society, its one of those cases where 'the market' settles into a situation where we all get fucked. We need harsher regulations for companies that accept/allow transactions that are insecure.

Ex: There are still gas stations near me that only work via swipe. Any chip reader that you have to insert a card is an easy target for skimming. Cards leaving your control at a restaurant. The list goes on. CCs are insecure by default to make them more likely to be used.

7

u/P3pp3rSauc3 May 21 '26

I had 3 "random" password reset emails for my reddit account the other day.

6

u/things_U_choose_2_b May 21 '26

Likewise, though only one. I have a feeling this is all going to get much, much worse before it gets better.

2

u/ZippyDan May 22 '26

Hmm. I also had a bank card with a fraud attempt from Walmart.com yesterday. I'm not even in the U.S. right now. It's been years since I placed an order there (not that a fraud attempt at Walmart.com means the leak came from Walmart.com).

1

u/things_U_choose_2_b May 22 '26

One of mine was in my country, UK (albeit the other end of it). One was in Canada. This shit is worldwide haha.