🚨A HACKER GROUP JUST STOLE 4,000 OF GITHUB'S OWN PRIVATE REPOSITORIES.. PUT THEM UP FOR SALE FOR $50,000.. AND THE WAY THEY GOT IN IS THE SCARIEST PART..
They didn't hack GitHub's servers.. They poisoned a VS Code extension.. One GitHub employee installed it.. And the attackers walked through the front door using the employee's own credentials..
The group calls themselves TeamPCP.. They name their malware after the sandworms from Dune.. And they've been running the most sophisticated supply chain attack campaign in cybersecurity history..
Here's how the whole thing unfolded..
In March.. They poisoned Trivy.. One of the most trusted security scanners in the world.. Used by over 10,000 development workflows globally..
They injected credential-stealing malware into Trivy's official GitHub Action.. The malware ran silently BEFORE the security scan.. So every log showed "scan completed successfully" while the malware was stealing AWS keys, SSH credentials, database passwords, and Kubernetes tokens in the background..
It took Aqua Security 5 days to fully remove them..
Using the stolen credentials.. They breached Cisco Systems.. Cloned over 300 private repositories.. Including source code for unreleased AI products.. And repositories belonging to Cisco's customers.. Major banks.. Government agencies.. BPO firms..
In April.. They hit Checkmarx.. Another security vendor.. Poisoned 5 official Docker images in 83 minutes.. The scanner worked perfectly.. It just silently sent all your secrets to the attackers..
That automatically cascaded into Bitwarden.. The password manager.. Their CI/CD system pulled the poisoned Docker image.. And the attackers injected malware into Bitwarden's official CLI package published on npm..
One compromised security scanner poisoned a password manager.. Automatically.. No human involved..
In May.. They hit TanStack.. Libraries downloaded millions of times per week.. 84 malicious package versions across 42 packages..
And here's the terrifying part..
The malware scraped the raw memory of GitHub's build servers.. Extracted authentication tokens.. Used those tokens to bypass two-factor authentication.. And then published the infected packages with completely valid cryptographic signatures..
Every security verification tool on earth said the packages were legitimate.. Because they were signed by the real pipeline.. Using real keys.. The attackers just happened to be inside the pipeline when it signed..
They defeated the entire trust model of modern software supply chains..
The same week they hit the Nx Console VS Code extension.. 2.2 million installations.. The malware specifically targeted Claude Code configurations.. Hunting for AI assistant credentials..
That's a first.. Supply chain malware designed to steal your AI's access keys..
Then on May 19.. They revealed the GitHub breach.. 4,000 internal repositories.. Listed for sale at $50,000.. With a warning.. "If nobody buys it.. We leak everything for free"..
Their malware is self-propagating.. Once it infects one package.. It automatically finds every other package that developer maintains.. Steals the publish tokens.. And infects all of them.. Then those packages infect the next developer.. And the next..
It jumps between npm and PyPI automatically..
The group doesn't even do the extortion themselves.. They sell stolen credentials to ransomware gangs.. One gang used TeamPCP's data to threaten Cisco with leaking FBI and NASA personnel records..
And the scariest part of all..
They didn't break any encryption.. They didn't find any zero-days.. They exploited the fact that the entire software industry blindly trusts its own build tools..
Every security scanner.. Every Docker image.. Every VS Code extension.. Every GitHub Action.. Is a potential weapon if someone poisons it upstream..
And right now.. Nobody can tell the difference between a legitimate build and a compromised one..
Because the compromised ones have valid signatures too.
We mapped all 18 wallets. Same funder, same week, same dust tokens, same test-transfer destination. One operator.
DWF Labs is officially partnered with MemeCore and linked on-chain to SIREN's controlling cluster. That's two of your flagged tokens connected by one entity.
https://t.co/cpCkj6ObA5
We mapped all 18 wallets. Same funder, same week, same dust tokens, same test-transfer destination. One operator.
DWF Labs is officially partnered with MemeCore and linked on-chain to SIREN's controlling cluster. That's two of your flagged tokens connected by one entity.
https://t.co/cpCkj6ObA5
@CtrlAltDwayne https://t.co/9WhvssdHNm answer isn't vibe coding its structure action coding most people don't know what they want to build and that's the problem they just start and don't know what goes into the project
The AI industry measures capability, cost, and speed.
Nobody measures whether a model can be someone consistently.
We built the first open benchmark for it. 22 models. 22,200 calls. $115.
Budget models beat frontier by 20%.
https://t.co/14OjyMFQhC
#AI#LLM#LLMEvaluation #BehavioralAI #PersonaFidelity #RLHFParadox
@thematrixb0t yeah bitcoin is finite something they actively were against when they make the gold standard disapear and sold all of the US gold to France and other Nations
@KomisarZack@G27football He was effective everywhere he went lol. He just never was the feature and maybe that’s what he’s doing bruhhh. Give Gibbs going to bama
@Camelliaaa__ Don’t give up just need to find someone that gives you the right energy. Dating culture sucks and that’s not your fault you deserve to find someone ❤️
@trad_west_ This is so funny to me because less than 1% of Texas population is Muslim and probably less than that actually practices in Islam like they would actually be able to vote that in.