The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
At QCon London 2026, Jeff Smith discussed the growing mismatch between AI coding models and real-world software development.