02/04/2026
ADVISORY | Cyberattacks Targeting Online Code Repositories
The National Cyber Security Center (NCSC) is alerting all Government departments, agencies, organizations, and users about increased cyberattacks targeting online code repositories. This advisory applies to anyone who manages code, publishes software, or uses third-party packages from online sources.
Threat actors are gaining access to repositories through phishing, vishing, social engineering, stolen credentials, compromised authentication tokens, and infected software packages. Once access is gained, they may modify software packages to spread attacks, search for passwords and sensitive data, leak stolen information publicly, or change private repositories to public. These actions increase the risk of further attacks and expose organizational systems.
To reduce risk, organizations should check systems and logs for unusual activity, use only trusted and verified software packages, and ensure staff are aware of the risks of unverified packages. It is also important to enable security features within code repositories to detect suspicious activity and immediately change any exposed passwords, keys, or tokens.
Compromised software packages present a serious risk because they are often widely used across multiple systems. Organizations should always know what software and versions they are using and keep accurate records.
Immediate action is required to protect systems and data. For support or to report an incident, contact the National Cyber Security Center (NCSC).
Let’s work together to keep Papua New Guinea’s digital space safe.