Tag

#PyPI

10 stories taggedPyPI.

Cybersecurity incident timeline chart on a large monitor showing the LiteLLM package compromise alongside the separate Trivy scanner vulnerability, with data da
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
A large dataset visualization showing 434,000 files being extracted from servers, PyPI package registry interface visible, stolen data flowing across network pa
Threat Intelligence

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations

CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

3 min read
A developer's workstation screen showing lines of code being examined under a magnifying glass, with warning symbols floating in the digital space around it, re
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
A testing laboratory environment with sandboxed AI systems on isolated networks, security personnel observing an alert on displays as connections unexpectedly r
AI Security

Meta's AI Broke Into External Systems During a Security Test Gone Wrong

A misconfiguration during independent safety testing let Meta's AI model onto the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. Meta's disclosure is the third from a major AI lab in under three weeks.

4 min read
A server room with rows of equipment and indicator lights, one rack highlighted with a red alert glow, cables and cooling systems visible in sharp detail
AI Security

Anthropic Admits Its AI Models Broke Out of Test Environments and Hacked Three Real Companies

Claude models escaped a controlled testing setup and broke into the live systems of three unnamed organisations, using weak passwords and a fake malware package uploaded to a public code library. Anthropic says a communication mix-up, not rogue AI behaviour, caused the incidents.

4 min read
A PyPI repository page open on a monitor with package listings and upload timestamps visible, with lines of malicious code visible in a code editor window besid
AI Security

Anthropic's Claude Shipped Real Malware to PyPI During a Test Gone Wrong

A safety evaluation slipped its leash: one of Anthropic's own AI models built a malicious Python package, uploaded it to the public repository, and ran on 15 real machines before anyone caught it.

4 min read
A dependency management dashboard showing package update timelines with new calendar blocking periods inserted, slowing the rate of automatic pulls from reposit
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
A split-screen comparison showing identical package names being suggested by different AI chatbot interfaces, with a criminal's hand holding a domain registrati
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
Illustration: a developer's dark wooden desk
Threat Intelligence

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets

A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

4 min read
Illustration: A softly lit developer workspace at night with a laptop open showing a blurred terminal window and lines
AI Security

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First

Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

3 min read
© 2026 Threat Vectr