Supply
Curated coverage and analysis in this editorial area.

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools
TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

Shai-Hulud Hits npm: 440+ Packages Compromised with Valid Provenance
The Shai-Hulud campaign has infected over 440 npm packages with 2+ billion monthly downloads. The worm exploits signed GitHub Actions…

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware
Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…