A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

More Technology news · Trending news

Published 5/21/2026, 9:00:00 AM · Updated 5/21/2026, 2:01:48 PMBy TheBriefWire Editorial Team

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

Key points

  • A so-called software supply chain attack, in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous foothold in a victim’s network.
  • Now one group of cybercriminals has turned that occasional nightmare into a near-weekly episode, corrupting hundreds of open source tools, extorting victims for profit, and sowing a new level of distrust in an entire ecosystem used to create the world’s software.
  • On Tuesday night, open source code platform GitHub announced that it had been breached by hackers in one such software supply chain attack: A GitHub developer had installed a “poisoned” extension for VSCode, a plug-in for a commonly used code editor that, like GitHub itself, is owned by Microsoft.
  • As a result, the hackers behind the breach, an...

Published May 21, 2026.


📌 Source: Andy Greenberg, Lily Hay Newman

BriefWire The BriefWire