Cloud Security

Poisoned npm Packages Steal AI Tokens and Spread Them Across Developer Build Environments

Cybercriminals are increasingly targeting AI API tokens through poisoned npm packages, turning ordinary developer environments into credential-harvesting machines. The stolen tokens can be abused...

LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD Environments

A major software supply chain breach involving LiteLLM has reportedly exposed credentials, cloud keys, API tokens, and internal configuration data from thousands of enterprise...

Cybercrime Markets Keep Selling Enterprise Access Despite Forum Takedowns and Arrests

Dark web markets remain active despite forum seizures, arrests, and disruption campaigns. Criminal groups quickly move to new platforms, copycat forums, encrypted channels, and...

LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts

A supply chain compromise involving LiteLLM highlights how a short-lived malicious package can create long-term risks across cloud environments, CI/CD systems, source-code repositories, Kubernetes...

ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine

A newly identified npm supply-chain worm called ChainDrop is turning stolen developer credentials into an automated package-infection system. The malware has reportedly compromised more...

Popular

Subscribe