
LiteLLM Attack: Bifrost, Kosong Alternatives
LiteLLM v1.82.7/1.82.8 on PyPI infected with credential-stealing malware. Alternatives: Bifrost (Go, 50x faster), Kosong (agent-focused), Helicone (observability). Easy migrations suggested.
Tag: #supply-chain-attack33 results

LiteLLM v1.82.7/1.82.8 on PyPI infected with credential-stealing malware. Alternatives: Bifrost (Go, 50x faster), Kosong (agent-focused), Helicone (observability). Easy migrations suggested.
A compromised npm package via hijacked publish token released a malicious Cline CLI update. It secretly installed OpenClaw on about 90,000 weekly users' machines. The attack lasted eight hours before detection.

Security firm Arctic Wolf discovered nearly 300 malicious GitHub repositories impersonating popular software brands. These repos distribute the BoryptGrab malware to steal sensitive data including browser credentials and crypto wallets.

The Arch User Repository (AUR) recently faced a security breach where malicious actors compromised over 400 packages. The injected code installed NPM-based keyloggers and information stealers, highlighting significant supply chain risks.

A hacking group known as TeamPCP claims to have stolen 3,800 internal GitHub source code repositories. The group is currently attempting to sell the data, framing it as a direct commercial transaction rather than a ransom.

OpenAI reported a supply chain attack that compromised two employee devices and potentially leaked code-signing certificates. While no customer data was affected, users are urged to update their macOS application by June 12.

Vercel disclosed unauthorized access to its systems, potentially leaking some users' environment variables. The attack originated from a third-party AI tool used by an employee that had reached end-of-support. It began with a Google Workspace account hijacking.
OpenAI responded to a supply chain attack on the Axios developer tool. They rotated macOS code signing certificates and updated apps. No user data was compromised.

EU Commission cloud environment breached via supply chain attack on open-source Trivy tool. TeamPCP hackers used tainted Trivy to steal AWS API keys. They extracted 92GB compressed data (340GB uncompressed) from Europa.eu infrastructure.

In March 2026, TeamPCP compromised Trivy, Checkmarx KICS, LiteLLM, and axios via CI/CD pipelines, injecting credential-stealing malware. Attacks exploited GitHub Actions and package publishes, exfiltrating secrets from pipelines. GitLab outlines how centralized policies can detect and block such threats.