TeamPCP ha compromesso centinaia di pacchetti open source su GitHub, npm e PyPI distribuendo malware attraverso repository compromessi.

GitHub has confirmed that roughly 3,800 internal repositories were hacked after an employee installed an infected VS Code extension.

GitHub says it has already rotated critical secrets and credentials following the breach