this post was submitted on 22 May 2026
69 points (94.8% liked)

Technology

84834 readers
4334 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 8 comments
sorted by: hot top controversial new old
[–] Juan_de_Silentio@lemmy.world 5 points 1 hour ago

Almost certainly a foreign government, or at least state sponsored.

[–] MightEnlightenYou@lemmy.world 17 points 2 hours ago (1 children)

Lol, the "big news" is an infected VScode extension with 4k users stealing 3k github credentials...

[–] A_norny_mousse@piefed.zip 2 points 56 minutes ago

The one Microsoft itself fell victim to recently, with their faltering github platform?

[–] A_norny_mousse@piefed.zip 1 points 55 minutes ago* (last edited 54 minutes ago)

The way I'm reading the article, this is mostly a Github thing:

The malware allows TeamPCP’s hackers to steal credentials (on github) that let them publish malicious versions of those software development tools, too (on github). The cycle repeats, and TeamPCP’s collection of breached networks grows.

[–] etherphon@piefed.world 19 points 3 hours ago (1 children)

Watching this from the sidelines is a lot lamer than the movies make it seem.

[–] panda_abyss@lemmy.ca 2 points 2 hours ago (1 children)

For what it’s worth, we are living close to the movie Hackers, complete with turning tankers upside down and a new RCE/LPE a day lately.

[–] etherphon@piefed.world 1 points 1 hour ago

I suppose it's just the culture that's just kind of flat, I thought it would be more universal but everyone is in their own bubbles so it's fractured all over the place, which is neat for the niches but there's no glue.

[–] Kiernian@lemmy.world 6 points 2 hours ago

I wonder who made the list of "don't touch these repos, they're propping up our proprietary software sans attribution" for the LLM injectabots to avoid.

I realize that the end game here is SUPPOSED to be "erode all trust in free software" but the ineptitude of those profiting off of proprietary software is such that they WILL fuck this up in such a way that it hurts themselves too, it's just a matter of when.