started · updated
Software supply-chain attacks and AI tool vulnerabilities expose industry security gaps
Threat group TeamPCP has injected malicious code into more than 1,000 open‑source software packages in under four months, exploiting the software industry’s emphasis on rapid code shipping over security. The attacks leverage automated CI/CD pipelines and AI‑driven tools, compromising trust in third‑party dependencies. Google’s threat intelligence traced the operator’s IP addresses to South Africa, indicating a likely individual actor.
Separately, an internal audit of the AI coding assistant Claude Code revealed extensive governance failures. Two high‑severity CVEs demonstrated that a malicious repository could execute arbitrary shell commands or redirect API traffic, stealing developers’ Anthropic API keys. The audit found unmanaged API keys, lack of traffic visibility, and no filesystem controls. Remediation steps included issuing managed keys, adding CI checks for configuration files, and redefining security policies for terminal‑based AI tools.