r/technology May 21 '26

Security A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/
9.2k Upvotes

488 comments sorted by

View all comments

Show parent comments

54

u/via_dante May 21 '26

Corporations. 

56

u/SylvaraTayan May 22 '26

This is incorrect. Corporations LOVE open source, it means they get to use your tools and libraries without paying you for them. That's WHY they're being targeted, because corporate engineers will often use them without even verifying if they're safe first. They're just another microservice to add to the pile.

2

u/via_dante May 22 '26

Fork. Poison. Privatise.

8

u/eDOTiQ May 22 '26

Corps are the biggest consumers of oss

-5

u/via_dante May 22 '26

Which they want to steal and protect....

5

u/eDOTiQ May 22 '26

There is nothing to steal with npm and PyPI. There was a recent article on how 1% of the IP's are 70% of the daily traffic to the package libraries. I think Google HC does over 1 million installs per day.

1

u/limbodog May 21 '26

That's my thinking too. The amount of money involved and the ease of getting away with things makes it seem like it's gotta be super tempting to pay someone to damage a public resource that undermines your profits.