Advertisement
Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft
AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.
Open Source Security: Key Findings from 2025 Trust Report
Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.
TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware
Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.
Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD
A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.
Claude Code Source Leaked via npm Packaging Error
Anthropic confirms internal Claude Code source code was leaked due to an npm packaging error. Analysis of supply chain risks and mitigation strategies.
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.
Advertisement
UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2
North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.
Axios NPM Compromise: Supply Chain Threat Analysis
Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.
Anthropic Claude Code Source Code Leaked via NPM Registry
Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.
Cisco Source Code Stolen: Trivy Supply Chain Attack Leads to Breach
Threat actors breached Cisco's dev environment using credentials from a Trivy supply chain attack, stealing proprietary and customer source code.
Axios npm Package Hijacked: Cross-Platform Malware Distribution
Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.
Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4
Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.
TeamPCP Supply Chain Campaign: Databricks and AstraZeneca Impact
TeamPCP's supply chain campaign weaponizes security scanners for dual ransomware operations, impacting Databricks and AstraZeneca in a major breach.
TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise
Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.
Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware
Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.
Telnyx PyPI Package Compromised by TeamPCP via Steganography
TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.
TeamPCP Supply Chain Attack: Telnyx PyPI Compromise and Vect Ransomware
TeamPCP campaign escalates with Telnyx PyPI compromise and Vect Ransomware mass affiliate program. Critical update for software developers and SOC teams.
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.
FCC Router Ban: Analyzing Supply Chain Risks & Consumer Security
The FCC's ban on foreign-made consumer routers aims to enhance national security but raises concerns about supply chain transparency, grey markets, and actual consumer…
TeamPCP Supply Chain: Checkmarx Wider Scope & LiteLLM PyPI Compromise
An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.
Risks of AI-Driven Dependency Resolution and Software Maintenance
AI models often hallucinate version numbers and ignore security fixes during dependency resolution, increasing technical debt and supply chain risks.
TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code
TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.
FCC Bans Foreign-Made Routers Over National Security Concerns
The FCC has prohibited the importation of new foreign-made routers to mitigate supply chain risks and protect critical communication infrastructure from adversaries.
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.