WorkThe story, in brief

A hacker group is poisoning open source code at an unprecedented scale

Open source infrastructure that powers AI development is under siege. TeamPCP's supply chain attacks just hit GitHub at scale.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI companies and startups rely heavily on open-source libraries and dependencies. Poisoned code in the supply chain poses existential risk to model training pipelines, deployment infrastructure, and enterprise AI systems. This is a governance and security story that every AI leader needs to track.

The key facts

5 to know
  1. TeamPCP targeting open source at unprecedented scale

  2. GitHub confirmed as victim

  3. Software supply chain attack vector

  4. Impacts AI infrastructure dependencies

  5. May 2026 incident timeline

Go to the source

Ars Technicaarstechnica.com

Publisher excerpt: GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work