Affected Technology

Supply Chain incidents

Supply-chain compromise and dependency attacks

Matching incidents

7

Technology type

Topic

News NEW

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

CircleCIGitHubGitLabGoogleJenkinsMicrosoft
Low severity NEW

OpenAI Supply-Chain Compromise

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Low severity STABLE

Claude Security Vulnerability

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Low severity STABLE

Anthropic Supply-Chain Compromise

The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on SecurityWeek.

AnthropicSupply ChainBaselessIllegalJudge Says PentagonMeasures Against Anthropic
1 source: securityweek.com Updated 20d ago
Low severity STABLE

AI Supply-Chain Compromise

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

Remote Code ExecutionSupply ChainChargedAlleged TeamPCP HackersAustralia Over MajorSupply Chain Attacks
1 source: thehackernews.com Updated 24d ago

Back to intelligence feed