GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
Source: wiredsecurity
Source Link: https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/