Socket: TeamPCP, the gang claiming GitHub's repositories breach, also executed 20 “waves” of supply chain attacks recently, compromising 500+ pieces of software
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
Wired
Context & Ripple Effects
Related coverage ties TeamPCP’s claimed GitHub intrusion to a malicious VS Code extension and a TanStack npm supply-chain attack affecting roughly 3,800 internal repositories. Separate reporting describes the group exploiting open-source distribution and trust mechanisms to inject malware into more than 1,000 packages.
The reported 20 attack waves place the GitHub incident within a broader campaign rather than an isolated repository breach. Coverage of the Megalodon incident, in which automated commits infected thousands of repositories, underscores how repository-scale compromise can rapidly widen downstream exposure.
First-order effects
Organizations using software packages compromised across TeamPCP’s campaigns must identify affected dependencies, remove malicious versions, and review build and repository activity for follow-on access.
GitHub and affected maintainers face immediate pressure to contain compromised repositories and credentials, while reassessing controls around extensions, automated commits, and package publication.
Second-order effects
Development teams and security vendors will increase scrutiny of package provenance and repository automation, adding friction to dependency updates and maintainer workflows.
A breach spanning internal repositories and public-package channels makes a single-platform response insufficient: enterprises will need controls across developer endpoints, source control, CI/CD systems, and package registries.
Third-order effects
If repeated campaigns continue to exploit the same open-source trust paths, software supply-chain security will shift further from reactive malware scanning toward verification of identities, builds, and release provenance.
The pattern could concentrate influence among platforms and tooling providers able to enforce stronger defaults, while smaller maintainers face rising security and operational burdens.
The trend: TeamPCP’s campaign is part of the broader industrialization of software supply-chain attacks, where compromise of trusted developer tools and distribution paths scales faster than attacks on individual targets.
NEW: This week's GitHub breach is just the latest in a string of at least 20 software supply chain attacks carried out by the hacker group TeamPCP. @agreenberg.bsky.social and @lhn.bsky.social report: www.wired.com/story/teampc...
A #Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale | WIRED — “ #GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.” — https://www.wired.com/...
We're continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: https://github.com/.... Initially, Microsoft indicated to us
Github hack was via this extension nrwl.angular-console VSIX Starting to get detected by more than just VT now https://www.virustotal.com/... https://opensourcemalware.com/ ...
SECURITY ADVISORY: A malicious version of Nx Console v18.95.0 was published today at 2:36 PM CEST and was available for 11 minutes, until 2:47 PM CEST, when we patched the issue. Nx Console v18.100.0 is the latest safe version to use. More info: https://github.com/...
The Nx team is being transparent. Genuinely. But “28 installs per Microsoft” vs “6000 activations per our analytics” is a hell of a gap for one supply-chain weekend. If download stats are that wrong for a 2.2M-install extension — what else are we undercounting in the npm and
@akses_0x00 @NxDevTools We published the detailed security advisory on GitHub and posted about it on X and Discord immediately after patching on Monday. I'm actually still waiting for confirmation from GitHub that Nx Console was the unnamed VSC extension in their postmortem, but …
Looks like this is the extension that popped GitHub. So the hackers used the same MO as npm worm - but instead of a wormy boy - they pushed a malicious VS Code extension out. Nx Console says they see evidence of ~6k downloads of the malware.
2026 is awesome. '"We are here today to advertise GitHub's source code and internal orgs for sale," TeamPCP wrote on BreachForums... “Everything for the main platform is there..."' new from @agreenberg.bsky.social & @lhn.bsky.social in @wired.com www.wired.com/story/teampc... @g…
The Nx Dev Tools CEO confirms that his company's Nx Console VS Code extension served as the initial entry point for the GitHub repo hack: https://x.com/... Nx incident: https://github.com/... Step Security report: https://www.stepsecurity.io/ ...