Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
46 items
Mistral AI SDK, TanStack Router hit in npm software supply chain attack
May 12, 2026MediumNewsSecurityIndustryThe TeamPCP threat group compromised about 170 npm and PyPI packages on May 11, including the @tanstack TanStack Router ecosystem of 42 packages, the Mistral AI SDK suite on npm and PyPI, and the Guardrails AI PyPI package. The attackers exploited the pull_request_target trigger and GitHub Actions weaknesses to hijack release pipelines and obtain maintainers' short-lived OIDC tokens, then injected the Mini Shai-Hulud malware, which spread through the worm capabilities of the platform. The malware is designed to steal developer credentials, and it installs a destructive monitor that attempts to delete the home directory if a stolen GitHub token is revoked.
Fix: SafeDep recommends checking the lockfile for known compromised versions, pinning dependencies to known good versions, checking for evidence of malware files, and rotating any credentials in use at the time of import if an infected version is suspected. SafeDep has published a full list of affected packages with indicators of compromise.
CSO OnlineTanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack
May 12, 2026MediumNewsSecurityIndustryA new coordinated Mini Shai-Hulud supply chain attack compromised over 170 packages across NPM and PyPI, including 42 TanStack packages, 65 UiPath packages, Mistral AI's PyPI packages, the OpenSearch JavaScript client, and the Guardrails AI PyPI package. TeamPCP was blamed for the campaign, which targets developer credentials, API keys, tokens, cloud credentials, cryptocurrency wallets, and AI tool secrets, and propagates using compromised NPM and GitHub Actions tokens. In the TanStack attack, the attackers chained three weaknesses, including a pull_request_target misconfiguration and GitHub Actions cache poisoning, to extract an OIDC token and publish 84 malicious artifacts with valid SLSA provenance.
SecurityWeekMalicious Hugging Face model masquerading as OpenAI release hits 244K downloads
May 11, 2026MediumNewsSecurityIndustryA malicious Hugging Face repository named Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter release, copying its model card and including a malicious loader.py file. The repository reached the #1 trending position with approximately 244K downloads before removal, and HiddenLayer reported that its loader delivered a credential-stealing infostealer to Windows hosts.
CSO OnlineGemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack
May 7, 2026MediumNewsSecurityIndustryPillar Security reports a critical flaw in Gemini CLI, the open source AI agent, rated CVSS 10/10 but lacking a CVE identifier. In --yolo mode, Gemini CLI ignored tool allowlists, so an attacker could hide malicious prompts in a public GitHub issue and have the agent triage it run commands, extract build-environment secrets and send them to an attacker-controlled server. Pillar says at least eight other Google repositories used the same vulnerable workflow template.
Fix: Google addressed the vulnerability on April 24 in Gemini CLI version 0.39.1, which evaluates tool allowlisting under --yolo mode. The run-gemini-cli GitHub Action was also updated. The update additionally resolved a lax trust issue in headless mode, which automatically trusted the current workspace folder.
SecurityWeekSupply-chain attacks take aim at your AI coding agents
May 5, 2026MediumNewsSecurityIndustryReversingLabs researchers tracked PromptMink, a supply-chain campaign attributed to North Korea's Famous Chollima that uses "LLM Optimization (LLMO) abuse and knowledge injection" to make malicious packages more likely to be chosen by AI coding agents. The campaign began last September with the bait package @solana-launchpad/sdk and the malicious dependency @hash-validator/v2, which contained a JavaScript infostealer. Attackers later rotated in additional packages and shifted to compiled payloads, including Single Executable Applications and Rust-based NAPI-RS Node.js add-ons.
CSO OnlineCritical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
Apr 30, 2026MediumNewsSecurityIndustryNovee Security researchers found a critical remote code execution flaw in Gemini CLI, an open source AI agent for terminal access to Gemini, which Google patched in Gemini CLI and the 'run-gemini-cli' GitHub Action. Gemini CLI automatically trusted the current workspace folder and loaded any agent configuration in it without review, sandboxing or approval, so an attacker who planted a malicious configuration could run arbitrary commands on the host before sandbox initialization. The researchers said this could expose secrets, credentials and source code and enable token theft, lateral movement and supply chain attacks in CI/CD pipelines.
Fix: Google patched the flaw in both Gemini CLI and the 'run-gemini-cli' GitHub Action. The source does not give fixed version numbers or further configuration steps.
SecurityWeekNew Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Apr 29, 2026MediumNewsSecurityIndustryReversingLabs reported a North Korea-linked campaign it calls PromptMink, attributed to Famous Chollima (aka Shifty Corsair), in which malicious npm packages posing as crypto utility SDKs steal sensitive secrets. The packages were introduced via a February 28 commit to an autonomous trading agent that was co-authored by Anthropic's Claude Opus, and they give attackers access to users' crypto wallets and funds. The attack uses a phased design in which first-layer packages import second-layer malicious packages that are replaced when removed.
The Hacker News‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks
Apr 15, 2026MediumNewsSecurityIndustryResearchers warn that a flaw in Anthropic's Model Context Protocol lets unsanitized commands execute silently. The flaw could enable full system compromise across widely used AI environments.
SecurityWeekAnthropic ban heralds new era of supply chain risk — with no clear playbook
Mar 19, 2026InfoNewsPolicyIndustryThe Trump administration designated Anthropic a "supply chain risk" and banned its technology from Pentagon assets and other government systems. The designation leaves CISOs, particularly government contractors, needing to identify and remove Anthropic AI technology across their organizations without a clear view of where it is embedded. A March 6 Pentagon memo directs military components to remove Anthropic products within 180 days and requires contractors to certify compliance.
CSO OnlinePalantir is still using Anthropic's Claude as Pentagon blacklist plays out, CEO Karp says
Mar 12, 2026InfoNewsPolicyIndustryPalantir CEO Alex Karp told CNBC that Palantir still uses Anthropic's Claude while the Pentagon's designation of Anthropic as a supply-chain risk plays out. He said Palantir's products are integrated with Anthropic and will probably be integrated with other large language models in the future. The Department of Defense designated Anthropic a supply-chain risk last week, Anthropic has sued to reverse the designation, and the Pentagon plans to phase out Anthropic over six months.
CNBC TechnologyAnthropic sues Defense Department over supply chain risk designation
Mar 9, 2026InfoNewsPolicyIndustryAnthropic filed a complaint in San Francisco federal court against the Department of Defense after the agency labeled it a supply chain risk. The dispute followed weeks of conflict over whether the military should have unrestricted access to Anthropic's AI systems, which Anthropic had limited on mass surveillance of Americans and fully autonomous weapons. Anthropic called the DOD's actions unprecedented and unlawful.
TechCrunchAnthropic CEO says 'no choice' but to challenge Trump admin's supply chain risk designation in court
Mar 5, 2026InfoNewsPolicyIndustryAnthropic CEO Dario Amodei confirmed that the U.S. government declared the company a supply chain risk and said Anthropic has "no choice" but to challenge the designation in court. The designation requires defense vendors and contractors to certify they do not use Anthropic's Claude models in their Pentagon work, and Anthropic is the only American company ever publicly named a supply chain risk.
CNBC TechnologyThe Pentagon formally labels Anthropic a supply-chain risk
Mar 5, 2026InfoNewsPolicyIndustryThe Defense Department has formally labeled Anthropic a "supply-chain risk" after failed negotiations over acceptable use policies, according to a Wall Street Journal report citing one source. The designation bars defense contractors from working with the government if they use Claude in their products. The label is typically applied to foreign companies with ties to adversarial governments, and this is the first time it has been applied to an American company.
The Verge (AI)Anthropic labelled a supply chain risk by Pentagon
Mar 5, 2026InfoNewsPolicyIndustryThe US government has officially designated Anthropic a supply chain risk, the first time such a label has been applied to a US firm. The Pentagon's designation followed a dispute over Anthropic's refusal to grant the government unfettered access to its AI tools for mass surveillance and autonomous weapons.
BBC TechnologyIt’s official: The Pentagon has labeled Anthropic a supply-chain risk
Mar 5, 2026InfoNewsPolicyIndustryThe Department of Defense has notified Anthropic leadership that the company and its products are designated a supply-chain risk, according to Bloomberg, after weeks of conflict over military use of Anthropic's AI systems. The designation requires any company or agency working with the Pentagon to certify that it does not use Anthropic's models, a move critics call unprecedented.
TechCrunchAnthropic officially told by DOD that it's a supply chain risk even as Claude used in Iran
Mar 5, 2026InfoNewsPolicyIndustryThe Department of Defense has officially informed Anthropic's leadership that the company and its products are designated a supply chain risk, effective immediately, according to a senior department official. The label requires defense vendors and contractors to certify they do not use Anthropic's models in their Pentagon work, and Anthropic says it will challenge the designation in court.
CNBC TechnologyTech industry group expresses 'concern' to Pete Hegseth over supply chain risk label
Mar 4, 2026InfoNewsPolicyIndustryThe Information Technology Industry Council, whose members include Nvidia, Google, Microsoft, Apple, Amazon and Anthropic, sent a letter to Defense Secretary Pete Hegseth expressing concern over the designation of a U.S. company as a supply chain risk. The letter does not name Anthropic, which received the label after failing to reach terms with the Defense Department. The group argues that contract disputes should be resolved through negotiation or by selecting alternate providers, and that such emergency authorities are reserved for foreign adversaries.
CNBC TechnologyTech workers urge DOD, Congress to withdraw Anthropic label as a supply-chain risk
Mar 2, 2026InfoNewsPolicyIndustryHundreds of tech workers signed an open letter urging the Department of Defense to withdraw its designation of Anthropic as a supply-chain risk, and asking Congress to examine whether such authorities against an American technology company are appropriate. The designation followed Anthropic's refusal to give the military unrestricted access to its AI systems, after it declined to allow mass surveillance of Americans or autonomous weapons without a human in the loop. Anthropic said the designation is legally unsound and that it would challenge it in court.
TechCrunchNew Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Mar 2, 2026MediumNewsSecurityIndustryPalo Alto Networks Unit 42 researcher Gal Weizman reported CVE-2026-0628 (CVSS 8.8), an insufficient policy enforcement flaw in the WebView tag of Google Chrome prior to 143.0.7499.192. A malicious extension with basic declarativeNetRequest permissions could inject JavaScript into the Gemini Live panel at gemini.google.com/app, gaining access to the camera and microphone, screenshots of any website, and local files. Google patched the flaw in early January 2026.
Fix: Fixed in Chrome version 143.0.7499.192/.193 for Windows/Mac and 143.0.7499.192 for Linux.
The Hacker NewsPentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
Feb 27, 2026InfoNewsPolicyIndustryU.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate Anthropic a "supply chain risk" after negotiations over Claude broke down. Anthropic had requested exceptions barring mass domestic surveillance of Americans and fully autonomous weapons. Anthropic called the designation "legally unsound" and said a designation under 10 USC 3252 can only extend to Claude's use in DoW contracts.
The Hacker News
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.