Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
Checkmarx, a software security company, confirmed that credentials obtained through the Trivy attack enabled unauthorized access to its GitHub repositories and the…