Ongoing story · 3 reports

Software Supply-Chain Attacks in 2026

Attackers kept targeting trusted software providers in 2026, slipping malicious code into npm and PyPI releases and into scripts that vendors serve to their customers' sites. This page lists our incident reports in date order, each covering what was affected, how the attack worked, and the checks developers can run.

  1. LiteLLM on PyPI: Backdoored Builds, Secret Harvest, and .pth Persistence

    Reported malicious 1.82.7–1.82.8 on PyPI—import-time execution, credential theft, .pth-based interpreter startup hooks (host persistence), key concentration, hash pinning, remediation, and primary sources.

  2. Axios npm Incident: Phantom Dependency, RAT Dropper, and Supply-Chain Lessons

    Malicious axios@1.14.1 and axios@0.30.4 on npm—phantom plain-crypto-js in tarballs, RAT/C2 on port 8000, OIDC vs manual publish signals, npm response, CISA/Microsoft/Mandiant/GitHub primary links, and SignalStack’s defender checklist.

  3. Brevo supply-chain attack: a hardcoded Cloudflare key at the edge

    How a hardcoded Cloudflare API key let attackers inject ClickFix and a WordPress backdoor through Brevo scripts on Sept. 14, 2026, and what to check now.