Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware ...
A widely used Python package with more than 95 million monthly downloads has been compromised with credential-stealing ...
The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package ...
Malicious LiteLLM 1.82.7–1.82.8 via Trivy compromise deploys backdoor and steals credentials, enabling Kubernetes-wide ...
Anthropic has exposed Claude Code's source code, with a packaging error triggering a rapid chain reaction across GitHub and ...
Supply chain attacks feel like they're becoming more and more common.
Code hosting website GitHub announced today a new service for its customers that will allow developers and organizations an easy way to generate "packages" from their code. Packages are ...