







The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
Post Mortem: axios npm supply chain compromise · Issue #10636 · axios/axios
Post Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were...
Dependency cooldowns turn you into a free-rider
Against dependency cooldowns as a response to supply chain attacks

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

Security Update: Suspected Supply Chain Incident | liteLLM
As of 2:00 PM ET on March 24, 2026

Mercor on Twitter / X
The privacy and security of our customers and contractors is foundational to everything we do at Mercor. We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM.Our security team moved promptly to contain and…— Mercor (@mercor_ai) March 31, 2026
Download pumping: New npm deception technique for supply chain attacks
Learn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate.

Mercor Breach Linked to LiteLLM Supply-Chain Attack
A LiteLLM supply-chain compromise enabled attackers to harvest credentials and access internal environments at scale at Mercor. The firm was the first to confirm a
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

A GitHub Issue Title Compromised 4,000 Developer Machines
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

Mercor, a $10 billion AI startup, confirms it was caught up in a major security incident | Fortune
The high-flying startup that provides AI training data to OpenAI, Anthropic, and Meta confirms it was hit by a “supply-chain attack.”

The Cyber Resilience Act: A Five Alarm Fire
On October 21, 2016, CNN’s website was knocked offline. So was the BBC and Guardian’s. Amazon, Etsy and Shopify too, along with Quora, Reddit, and Twitter – among others. Huge swaths of the internet were taken down by a series of attacks on the DNS provider Dyn. These Distributed Denial of Service (DDoS) attacks were

What Liberal Media? Axios Thinks Being Neutral Means Kissing Trump’s Ass
The news org Axios launched in 2017, just as the first Trump administration began, created by some ex-Politico folks, claiming that they would be “an antidote to this madness” and talking about how…

I do wish it was better understood by now—especially by folks in the media—that these "warnings" from large AI corporations in fact function as "advertisements" axios.com/2025/04/22/ai-anthropic-virtu…
Exclusive: Anthropic warns fully AI employees are a year away
www.axios.comI do wish it was better understood by now—especially by folks in the media—that these "warnings" from large AI corporations in fact function as "advertisements" axios.com/2025/04/22/ai-anthropic-virtu…
Exclusive: Anthropic warns fully AI employees are a year away
www.axios.com