MIT License 기반 Open Source 전환을 통한 Shai-Hulud 웜의 전파력 극대화
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Cache-poisoning caper turns TanStack npm packages toxic
Ongoing supply-chain attack 'explicitly targeting' security, dev tools
Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users
I watched Shai Hulud steal credentials from teams running npm audit. Here's the gap nobody talks about.
PyPI의 litellm 1.82.8 패키지가 .pth 파일 자동 실행 기능을 악용해 API 키·SSH 키·클라우드 토큰 등 모든 자격 증명을 탈취
LiteLLM loses game of Trivy pursuit, gets compromised
LiteLLM Python package compromised by supply-chain attack