GitHub Confirms Internal Repository Breach via Malicious VS Code Extension — TeamPCP Claims 3,800 Repos Stolen
GitHub has confirmed unauthorized access to its internal repositories after a malicious Visual Studio Code extension compromised an employee device. Threat actor TeamPCP claims to have exfiltrated approximately...
JDownloader Official Website Hijacked to Deliver RAT Malware in Windows and Linux Installers
Attackers compromised the official JDownloader website between May 6-7, 2026, replacing legitimate Windows and Linux installers with malicious versions containing a Python-based Remote Access Trojan. Users who downloaded...
TeamPCP Supply Chain Campaign Poisons Checkmarx KICS, Bitwarden CLI, and PyPI Packages to Steal Cloud Credentials at Scale
A financially motivated threat group tracked as TeamPCP has executed at least seven waves of sophisticated supply chain attacks since March 2026, poisoning trusted CI/CD tools including Checkmarx...
84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials
Attackers compromised 84 npm artifacts across 42 TanStack packages — including react-router with 12M+ weekly downloads — injecting a credential-stealing payload via chained GitHub Actions abuse. Organizations that...
Foxconn Confirms Cyberattack: Nitrogen Ransomware Gang Claims 8TB Stolen From North American Plants
Foxconn has confirmed a ransomware attack on its North American factories after the Nitrogen gang claimed to have stolen 8TB of data including technical drawings and network topology...
DigiCert Breached via Weaponized Screensaver: Threat Actor Steals EV Code Signing Certificates to Spread Zhong Stealer
A sophisticated threat actor breached DigiCert's internal support environment in early April 2026 by tricking analysts into executing a disguised .scr malware file, ultimately obtaining EV Code Signing...
Trellix Source Code Breach: Hackers Gain Unauthorized Access to Internal Repository of Major XDR Vendor
Cybersecurity vendor Trellix has confirmed unauthorized access to part of its internal source code repository. The company says no evidence of product tampering or active exploitation has been...
Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack
Security researchers at Socket have confirmed that the official Bitwarden CLI npm package (version 2026.4.0) was tampered with via a compromised GitHub Actions workflow, injecting credential-stealing malware as...