Open-source supply chain breach raises alarm