







Supply chain security for ML

Security Update: Suspected Supply Chain Incident | liteLLM
As of 2:00 PM ET on March 24, 2026

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

MCP and LLM Security Research Briefing | Wiz Blog
Explore the evolving Model Context Protocol (MCP), its security risks, and how to prepare for safe adoption as LLMs connect to external systems.

Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.

Mercor on Twitter / X
The privacy and security of our customers and contractors is foundational to everything we do at Mercor. We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM.Our security team moved promptly to contain and…— Mercor (@mercor_ai) March 31, 2026

Model Context Protocol has prompt injection security problems
As more people start hacking around with implementations of MCP (the Model Context Protocol, a new standard for making tools available to LLM-powered systems) the security implications of tools built …

Secret Manager
Securely store API keys, passwords, certificates, and other sensitive data with Google Cloud’s Secret Manager.
VaultGemma: The world's most capable differentially private LLM
Amer Sinha, Software Engineer, and Ryan McKenna, Research Scientist, Google Research

Inside Google’s Ironwood TPU v7 Supply Chain
Dear visitor, by reading this article, you acknowledge that you have reviewed and agree to the disclaimer outlined on this Substack.

Confidential Inference via Trusted Virtual Machines
Announcing a new collaborative research paper on Confidential Inference, a set of tools to improve the security of our model weights and of our users' data

Mercor Breach Linked to LiteLLM Supply-Chain Attack
A LiteLLM supply-chain compromise enabled attackers to harvest credentials and access internal environments at scale at Mercor. The firm was the first to confirm a
Encryption + Trust & Safety reading list (updated 2026-05-20)
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

Building a Browser-Native Verification Stack for Tinfoil
Learn how we built a browser-based confidentiality and integrity verifier with implementations of browser-native Sigstore and TUF libraries.
