Apr 04, 2026 β’
Malware
|
#Claude AI
#Malware
#Supply Chain Attack
Threat actors are weaponizing leaked Anthropic Claude AI source code by embedding malware, disguised as legitimate repositories, and distributing it to develope...
Read Analysis β
Apr 04, 2026 β’
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Data Breach
AI training startup Mercor experienced a data breach resulting from a supply chain attack that leveraged the open-source project LiteLLM, impacting potentially ...
Read Analysis β
Apr 03, 2026 β’
Malware
|
#LiteLLM
#Supply Chain Attack
#Malicious Code Injection
Attackers executed a supply-chain attack on the open-source library LiteLLM by exploiting stolen credentials to inject malicious code into its PyPI distribution...
Read Analysis β
Apr 03, 2026 β’
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Lapsus$
AI firm Mercor confirmed a breach stemming from a supply chain attack involving the open-source LiteLLM PyPI package, where attackers published malicious versio...
Read Analysis β
Apr 02, 2026 β’
Vulnerability
|
#Supply Chain Attack
#LiteLLM
#Software Integrity
Mercor was reportedly impacted by a supply chain attack involving the LiteLLM component, suggesting a potential compromise of software integrity or introduction...
Read Analysis β
Apr 01, 2026 β’
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Data Exfiltration
An extortion group executed a supply chain attack by compromising the open-source LiteLLM project, which serves as a widely-used AI model API proxy. This breach...
Read Analysis β
Apr 01, 2026 β’
Vulnerability
|
#LiteLLM
#Supply Chain Attack
#Malicious Code Injection
The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of ...
Read Analysis β
Apr 01, 2026 β’
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Lapsus$
Mercor, an AI recruiting startup, experienced a data breach following a supply chain attack on the open-source LiteLLM project, which involved the injection of ...
Read Analysis β
Mar 31, 2026 β’
Vulnerability
|
#LiteLLM
#Supply Chain Attack
#AI Agent Compromise
A sophisticated multi-stage supply chain attack, initiated by compromising open-source security scanner Trivy to steal LiteLLM PyPI credentials, injected malici...
Read Analysis β
Jan 30, 2026 β’
Vulnerability
|
#Prompt Injection
#Supply Chain Attack
#AI Agent Security
The OpenClaw AI assistant, an autonomous open-source agent, poses significant security risks due to its privileged access to system tools and sensitive data. It...
Read Analysis β
Dec 18, 2025 β’
Data Leak
|
#Mixpanel
#Supply Chain Attack
#API Data Exposure
An OpenAI security incident occurred due to a vulnerability in its third-party data analytics provider, Mixpanel. This breach exposed general user information, ...
Read Analysis β
Nov 11, 2025 β’
Malware
|
#AI-generated Malware
#Supply Chain Attack
#NullBulge Group
AI-enabled supply chain attacks are rapidly escalating, demonstrated by the NullBulge group weaponizing open-source repositories for data exfiltration and LockB...
Read Analysis β
Sep 24, 2025 β’
Data Leak
|
#OAuth token
#Supply Chain Attack
#AI Integrations
Threat actors (UNC6395) initiated a supply chain attack by compromising a Salesloft GitHub repository to exfiltrate a sensitive OAuth token. This token granted ...
Read Analysis β
Sep 24, 2025 β’
Data Leak
|
#OAuth Token Theft
#Supply Chain Attack
#AI Integration Security
A supply chain attack originating from a Salesloft GitHub repository led to the theft of an OAuth token, granting privileged access to their Drift account. This...
Read Analysis β
Sep 24, 2025 β’
Data Leak
|
#OAuth token
#Supply Chain Attack
#GitHub compromise
An OAuth token stolen from a compromised GitHub repository of AI chatbot vendor Salesloft-Drift was leveraged to access their high-privilege Drift account. This...
Read Analysis β
Aug 28, 2025 β’
Vulnerability
|
#Nx build system
#Supply Chain Attack
#AI-weaponized
Hackers exploited a vulnerable workflow in the Nx build system to achieve code injection and GITHUB_TOKEN theft, enabling the publication of malicious package v...
Read Analysis β
Jul 24, 2025 β’
Vulnerability
|
#Supply Chain Attack
#Prompt Injection
#Amazon Q
A hacker injected destructive system commands into Amazon's Visual Studio Code extension for Amazon Q via a compromised GitHub repository, distributing it ...
Read Analysis β