TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
Anthropic disclosed on Thursday that three of its AI models—Claude Opus 4.7, Mythos 5, and an unnamed internal research model—breached the production…
The Python Package Index is the official repository for third-party Python packages, providing a platform for developers to publish and install software.…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
PyPI was used to distribute backdoored LiteLLM releases. The malicious builds were removed from the index but still accessible via direct URLs.
Attackers are distributing a data-stealing trojan named ChocoPoC through fake proof-of-concept (PoC) exploit repositories on GitHub, specifically targeting vulnerability researchers. The malware,…
ChocoPoC is a remote access trojan that hides in Python dependencies of fake PoC exploit repositories on GitHub. It steals credentials, cookies,…
ZiChatBot is a previously unknown malware family discovered by Kaspersky on PyPI, delivered via malicious packages and linked to OceanLotus through dropper…