Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
84 items
Mistral AI SDK, TanStack Router hit in npm software supply chain attack
May 12, 2026MediumNewsSecurityIndustryThe TeamPCP threat group compromised about 170 npm and PyPI packages on May 11, including the @tanstack TanStack Router ecosystem of 42 packages, the Mistral AI SDK suite on npm and PyPI, and the Guardrails AI PyPI package. The attackers exploited the pull_request_target trigger and GitHub Actions weaknesses to hijack release pipelines and obtain maintainers' short-lived OIDC tokens, then injected the Mini Shai-Hulud malware, which spread through the worm capabilities of the platform. The malware is designed to steal developer credentials, and it installs a destructive monitor that attempts to delete the home directory if a stolen GitHub token is revoked.
Fix: SafeDep recommends checking the lockfile for known compromised versions, pinning dependencies to known good versions, checking for evidence of malware files, and rotating any credentials in use at the time of import if an infected version is suspected. SafeDep has published a full list of affected packages with indicators of compromise.
CSO OnlineCVE-2026-31223: snorkel insecure deserialization in BaseLabeler.load() via pickle files
May 12, 2026CriticalVulnerabilitySecurityCVE-2026-31223CVE-2026-31223 affects the snorkel library through v0.10.0 and is classified as CWE-502, insecure deserialization. The BaseLabeler.load() method passes user-supplied file paths to pickle.load() with no validation or security controls. A remote attacker who supplies a maliciously crafted pickle file can achieve arbitrary code execution when the file is loaded through this method.
NVD/CVE DatabaseTanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack
May 12, 2026MediumNewsSecurityIndustryA new coordinated Mini Shai-Hulud supply chain attack compromised over 170 packages across NPM and PyPI, including 42 TanStack packages, 65 UiPath packages, Mistral AI's PyPI packages, the OpenSearch JavaScript client, and the Guardrails AI PyPI package. TeamPCP was blamed for the campaign, which targets developer credentials, API keys, tokens, cloud credentials, cryptocurrency wallets, and AI tool secrets, and propagates using compromised NPM and GitHub Actions tokens. In the TanStack attack, the attackers chained three weaknesses, including a pull_request_target misconfiguration and GitHub Actions cache poisoning, to extract an OIDC token and publish 84 malicious artifacts with valid SLSA provenance.
SecurityWeekCVE-2026-31252: CosyVoice insecure deserialization in model loading via torch.load
May 11, 2026HighVulnerabilitySecurityCVE-2026-31252CosyVoice, through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21), has an insecure deserialization flaw (CWE-502) in its model loading component. The framework calls torch.load() on model weight files such as llm.pt, flow.pt and hift.pt without weights_only=True, so arbitrary Python objects can be deserialized through the pickle module. When a victim starts the CosyVoice Web UI pointing at a malicious model directory, arbitrary code runs on their system during model loading.
NVD/CVE DatabaseCVE-2026-31251: CosyVoice insecure deserialization in gRPC server model loading
May 11, 2026HighVulnerabilitySecurityCVE-2026-31251CosyVoice, through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21), has an insecure deserialization flaw (CWE-502) in its gRPC server component. On startup, the server loads the speech synthesis model from a user-specified directory with torch.load() without weights_only=True, so pickle can deserialize arbitrary Python objects. An attacker who places malicious model files in a directory that a victim points the server to gains arbitrary code execution during server initialization.
NVD/CVE DatabaseMalicious Hugging Face model masquerading as OpenAI release hits 244K downloads
May 11, 2026MediumNewsSecurityIndustryA malicious Hugging Face repository named Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter release, copying its model card and including a malicious loader.py file. The repository reached the #1 trending position with approximately 244K downloads before removal, and HiddenLayer reported that its loader delivered a credential-stealing infostealer to Windows hosts.
CSO OnlineGemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack
May 7, 2026MediumNewsSecurityIndustryPillar Security reports a critical flaw in Gemini CLI, the open source AI agent, rated CVSS 10/10 but lacking a CVE identifier. In --yolo mode, Gemini CLI ignored tool allowlists, so an attacker could hide malicious prompts in a public GitHub issue and have the agent triage it run commands, extract build-environment secrets and send them to an attacker-controlled server. Pillar says at least eight other Google repositories used the same vulnerable workflow template.
Fix: Google addressed the vulnerability on April 24 in Gemini CLI version 0.39.1, which evaluates tool allowlisting under --yolo mode. The run-gemini-cli GitHub Action was also updated. The update additionally resolved a lax trust issue in headless mode, which automatically trusted the current workspace folder.
SecurityWeekSupply-chain attacks take aim at your AI coding agents
May 5, 2026MediumNewsSecurityIndustryReversingLabs researchers tracked PromptMink, a supply-chain campaign attributed to North Korea's Famous Chollima that uses "LLM Optimization (LLMO) abuse and knowledge injection" to make malicious packages more likely to be chosen by AI coding agents. The campaign began last September with the bait package @solana-launchpad/sdk and the malicious dependency @hash-validator/v2, which contained a JavaScript infostealer. Attackers later rotated in additional packages and shifted to compiled payloads, including Single Executable Applications and Rust-based NAPI-RS Node.js add-ons.
CSO OnlineCritical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
Apr 30, 2026MediumNewsSecurityIndustryNovee Security researchers found a critical remote code execution flaw in Gemini CLI, an open source AI agent for terminal access to Gemini, which Google patched in Gemini CLI and the 'run-gemini-cli' GitHub Action. Gemini CLI automatically trusted the current workspace folder and loaded any agent configuration in it without review, sandboxing or approval, so an attacker who planted a malicious configuration could run arbitrary commands on the host before sandbox initialization. The researchers said this could expose secrets, credentials and source code and enable token theft, lateral movement and supply chain attacks in CI/CD pipelines.
Fix: Google patched the flaw in both Gemini CLI and the 'run-gemini-cli' GitHub Action. The source does not give fixed version numbers or further configuration steps.
SecurityWeekNew Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Apr 29, 2026MediumNewsSecurityIndustryReversingLabs reported a North Korea-linked campaign it calls PromptMink, attributed to Famous Chollima (aka Shifty Corsair), in which malicious npm packages posing as crypto utility SDKs steal sensitive secrets. The packages were introduced via a February 28 commit to an autonomous trading agent that was co-authored by Anthropic's Claude Opus, and they give attackers access to users' crypto wallets and funds. The attack uses a phased design in which first-layer packages import second-layer malicious packages that are replaced when removed.
The Hacker NewsGHSA-c2jg-5cp7-6wc7: Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Apr 23, 2026CriticalVulnerabilitySecurityCVE-2025-62373A critical flaw in Pipecat's LivekitFrameSerializer, an optional, non-default, undocumented serializer deprecated in version 0.0.90, passes untrusted WebSocket message data directly to pickle.loads() in deserialize() in src/pipecat/serializers/livekit.py. A remote client that can reach a server using this serializer, for example one bound to 0.0.0.0, can send a crafted pickle payload to execute arbitrary code on the server with the Pipecat service's privileges.
GitHub Advisory DatabaseCVE-2026-6859: InstructLab code execution via untrusted HuggingFace model loading
Apr 22, 2026HighVulnerabilitySecurityCVE-2026-6859CVE-2026-6859 affects InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace, so a remote attacker can achieve arbitrary Python code execution by persuading a user to run `ilab train/download/generate` with a crafted malicious model from the HuggingFace Hub. The weakness is classified as CWE-829, and NVD had not yet provided an assessment at publication.
NVD/CVE Database‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks
Apr 15, 2026MediumNewsSecurityIndustryResearchers warn that a flaw in Anthropic's Model Context Protocol lets unsanitized commands execute silently. The flaw could enable full system compromise across widely used AI environments.
SecurityWeekAnthropic ban heralds new era of supply chain risk — with no clear playbook
Mar 19, 2026InfoNewsPolicyIndustryThe Trump administration designated Anthropic a "supply chain risk" and banned its technology from Pentagon assets and other government systems. The designation leaves CISOs, particularly government contractors, needing to identify and remove Anthropic AI technology across their organizations without a clear view of where it is embedded. A March 6 Pentagon memo directs military components to remove Anthropic products within 180 days and requires contractors to certify compliance.
CSO OnlineGHSA-hqmj-h5c6-369m: ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
Mar 16, 2026HighVulnerabilitySecurityIndustryCVE-2026-28500onnx.hub.load() skips its trust check for untrusted model repositories when silent=True is passed, so no warning or confirmation prompt appears. The source states that the SHA256 check validates against a manifest that the attacker controls, so a malicious model can carry a matching hash. The source says that when chained with file-system vulnerabilities, a model loaded this way can silently exfiltrate files such as SSH keys and cloud credentials.
GitHub Advisory DatabasePalantir is still using Anthropic's Claude as Pentagon blacklist plays out, CEO Karp says
Mar 12, 2026InfoNewsPolicyIndustryPalantir CEO Alex Karp told CNBC that Palantir still uses Anthropic's Claude while the Pentagon's designation of Anthropic as a supply-chain risk plays out. He said Palantir's products are integrated with Anthropic and will probably be integrated with other large language models in the future. The Department of Defense designated Anthropic a supply-chain risk last week, Anthropic has sued to reverse the designation, and the Pentagon plans to phase out Anthropic over six months.
CNBC TechnologyAnthropic sues Defense Department over supply chain risk designation
Mar 9, 2026InfoNewsPolicyIndustryAnthropic filed a complaint in San Francisco federal court against the Department of Defense after the agency labeled it a supply chain risk. The dispute followed weeks of conflict over whether the military should have unrestricted access to Anthropic's AI systems, which Anthropic had limited on mass surveillance of Americans and fully autonomous weapons. Anthropic called the DOD's actions unprecedented and unlawful.
TechCrunchAnthropic CEO says 'no choice' but to challenge Trump admin's supply chain risk designation in court
Mar 5, 2026InfoNewsPolicyIndustryAnthropic CEO Dario Amodei confirmed that the U.S. government declared the company a supply chain risk and said Anthropic has "no choice" but to challenge the designation in court. The designation requires defense vendors and contractors to certify they do not use Anthropic's Claude models in their Pentagon work, and Anthropic is the only American company ever publicly named a supply chain risk.
CNBC TechnologyThe Pentagon formally labels Anthropic a supply-chain risk
Mar 5, 2026InfoNewsPolicyIndustryThe Defense Department has formally labeled Anthropic a "supply-chain risk" after failed negotiations over acceptable use policies, according to a Wall Street Journal report citing one source. The designation bars defense contractors from working with the government if they use Claude in their products. The label is typically applied to foreign companies with ties to adversarial governments, and this is the first time it has been applied to an American company.
The Verge (AI)Anthropic labelled a supply chain risk by Pentagon
Mar 5, 2026InfoNewsPolicyIndustryThe US government has officially designated Anthropic a supply chain risk, the first time such a label has been applied to a US firm. The Pentagon's designation followed a dispute over Anthropic's refusal to grant the government unfettered access to its AI tools for mass surveillance and autonomous weapons.
BBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.