Advertisement
Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP
Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.
Python Supply Chain: Malicious Packages Targeting Developers
Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.
Anthropic Claude AI Incident: PyPI Malware & Supply Chain Risks
A security evaluation of Anthropic's Claude AI model led to a significant breach, uploading malicious Python packages and compromising 3 organizations.
GitHub and PyPI Policy Updates Target Supply Chain Security
GitHub and PyPI introduce new restrictions to thwart supply chain attacks, including a Dependabot cooldown and limits on historical package file uploads.
GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks
GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.
Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials
Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.
Advertisement
Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets
New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.
TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub
TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.
TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis
TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
OpenAI Breach: TanStack Supply Chain Attack Impacts Employee Devices
OpenAI confirms two employee devices compromised in a TanStack supply chain attack affecting npm and PyPI packages, prompting certificate rotation.
Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages
The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.
PyPI Supply Chain Threat: Deceptive Packages Target Developers
Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.
Backdoored PyTorch Lightning Package Drops Credential Stealer
A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.
PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain
Threat actors injected malicious code into PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI, enabling credential theft via a supply chain attack.
TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks
TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.
Malicious PyPI Package elementary-data Hijacked for Infostealer
High-profile supply chain attack on the elementary-data PyPI package compromises developer credentials and crypto wallets via account takeover. Patch now.
litellm 1.82.8 Supply Chain Compromise via Malicious .pth File
Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.
TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise
Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.
Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware
Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.