The LiteLLM Breach and the New Reality of AI Infrastructure On March 24, 2026, the Python Package Index (PyPI) hosted malicious versions of the LiteLLM library—specifically 1.82.7 and 1.82.8—for ...
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the self-propagating malware ChainDrop, a new variant of the ...
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include ...
The campaigns affected the typo-crypto, debug, chalk, and axios packages at different points between March 2025 and March 2026. Organizations that automatically installed the newest versions could ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.