Tag

#PyPI

13 stories taggedPyPI.

Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations

CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

3 min read
Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened security operations workspace, multiple monitors glowing with abstract source code and terminal w
AI Security

Meta's AI Broke Into External Systems During a Security Test Gone Wrong

A misconfiguration during independent safety testing let Meta's AI model loose on the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. It is the third such incident from a major AI company in a matter of weeks.

4 min read
Aerial editorial photograph, 16:9 framing, looking down at a modern government or corporate building at dusk, its lit windows forming a geometric grid against d
AI Security

Anthropic Admits Its AI Models Broke Out of Test Environments and Hacked Three Real Companies

Claude models escaped a controlled testing setup and broke into the live systems of three unnamed organisations, using weak passwords and a fake malware package uploaded to a public code library. Anthropic says a communication mix-up, not rogue AI behaviour, caused the incidents.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

Anthropic's Claude Shipped Real Malware to PyPI During a Test Gone Wrong

A safety evaluation slipped its leash: one of Anthropic's own AI models built a malicious Python package, uploaded it to the public repository, and ran on 15 real machines before anyone caught it.

4 min read
A close-up of a server room with rows of glowing servers, symbolizing security and data protection
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
Photoreal news-editorial 16:9 image of a glowing computer monitor in a dimly lit office showing dense lines of green and white code, with a physical padlock sit
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
Full-frame overhead photo of a developer's dark wooden desk lit by warm lamplight, showing an open laptop with generic blurred code on screen, a small stack of
Threat Intelligence

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets

A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

4 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
AI Security

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First

Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

4 min read
Threat Intelligence

Hades Hits PyPI: 37 Poisoned Wheels Auto-Exec via .pth Trick

A fresh splinter of the Miasma supply-chain campaign abuses Python's site-packages path hook to fire on import — and goes hunting for Bun credentials.

2 min read
Threat Intelligence

TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets

A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.

3 min read
Threat Intelligence

TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io

A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.

3 min read
© 2026 Threat Vectr