Technology · Singapore Bureau
Two arrested in Australia over software supply chain attack
Australian authorities have apprehended two men suspected of injecting malicious code into widely-used open-source software, potentially affecting over 1,000 organisations worldwide. The attack represents a significant threat to global software supply chains, according to police.
LSN Singapore ·

The arrests mark a major development in one of the technology sector's most serious security incidents. Investigators allege the suspects compromised popular open-source code repositories, allowing them to distribute tainted software across international networks. The full scope of the operation and the identities of affected organisations are still being determined.
Open-source software forms the backbone of digital infrastructure globally, with developers relying on shared code repositories to build applications and systems. A successful attack at this level can propagate rapidly across multiple sectors, from finance to healthcare, as organisations unknowingly integrate the compromised code into their operations.
Police said the malicious code posed significant risks to cybersecurity and could have enabled unauthorised access to sensitive systems and data. The investigation involved coordination between Australian authorities and international partners concerned about the potential for widespread exploitation. Further details about the sophistication of the attack and the methods used to conceal the malicious instructions are expected as the case develops.
The incident underscores growing concerns about the security of open-source software ecosystems and the need for enhanced oversight of shared code repositories. Industry experts have long warned that supply chain attacks represent an increasingly favoured target for sophisticated threat actors seeking to compromise multiple organisations simultaneously.