tech

Trust is the target: the new AI-era supply-chain attacks

Hackers are not really breaking in any more. They are walking through doors we hold open for them.

Trust is the target: the new AI-era supply-chain attacks

TL;DR

  • Hackers are increasingly exploiting open-source code and AI tools instead of traditional intrusion methods.
  • The group TeamPCP has injected malicious code into over 1,000 open-source packages, affecting major companies like Red Hat and SAP.
  • AI coding agents can be hijacked through fake bug reports, and poisoned editor extensions have led to the theft of GitHub repositories.
  • Attackers have used Anthropic's Claude AI by creating fake "Apple Support" chats to trick macOS developers into running malicious commands.
  • The core issue is the exploitation of trust in familiar tools and platforms, such as package registries, AI agents, and trusted domains.