Ongoing story · 3 reports
Software Supply-Chain Attacks in 2026
Attackers kept targeting trusted software providers in 2026, slipping malicious code into npm and PyPI releases and into scripts that vendors serve to their customers' sites. This page lists our incident reports in date order, each covering what was affected, how the attack worked, and the checks developers can run.
-
LiteLLM on PyPI: Backdoored Builds, Secret Harvest, and .pth Persistence
Reported malicious 1.82.7–1.82.8 on PyPI—import-time execution, credential theft, .pth-based interpreter startup hooks (host persistence), key concentration, hash pinning, remediation, and primary sources.
-
Axios npm Incident: Phantom Dependency, RAT Dropper, and Supply-Chain Lessons
Malicious axios@1.14.1 and axios@0.30.4 on npm—phantom plain-crypto-js in tarballs, RAT/C2 on port 8000, OIDC vs manual publish signals, npm response, CISA/Microsoft/Mandiant/GitHub primary links, and SignalStack’s defender checklist.
-
Brevo supply-chain attack: a hardcoded Cloudflare key at the edge
How a hardcoded Cloudflare API key let attackers inject ClickFix and a WordPress backdoor through Brevo scripts on Sept. 14, 2026, and what to check now.