A hacker group is poisoning open source code at an unprecedented scale
Open source infrastructure that powers AI development is under siege. TeamPCP's supply chain attacks just hit GitHub at scale.

Why it matters
AI companies and startups rely heavily on open-source libraries and dependencies. Poisoned code in the supply chain poses existential risk to model training pipelines, deployment infrastructure, and enterprise AI systems. This is a governance and security story that every AI leader needs to track.
The key facts
5 to knowTeamPCP targeting open source at unprecedented scale
GitHub confirmed as victim
Software supply chain attack vector
Impacts AI infrastructure dependencies
May 2026 incident timeline
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.