Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
46 items
Defense secretary Pete Hegseth designates Anthropic a supply chain risk
Feb 27, 2026InfoNewsPolicyIndustryDefense Secretary Pete Hegseth designated Anthropic a "supply-chain risk" shortly after President Donald Trump announced a ban on Anthropic products across the federal government. The decision could immediately affect major tech companies that use Claude for Pentagon work, including Palantir and AWS, and it is unclear how far the Pentagon may extend restrictions to companies using Claude for non-national-security services.
The Verge (AI)Pentagon moves to designate Anthropic as a supply-chain risk
Feb 27, 2026InfoNewsPolicyIndustryPresident Trump directed federal agencies to cease using all Anthropic products after the company's public dispute with the Department of Defense, allowing a six-month phase-out. Secretary of Defense Pete Hegseth then directed the Department of War to designate Anthropic a Supply-Chain Risk to National Security, barring contractors and partners doing business with the US military from commercial activity with Anthropic. The dispute centered on Anthropic's refusal to allow its models to power mass domestic surveillance or fully autonomous weapons.
TechCrunchNew ‘Sandworm_Mode’ Supply Chain Attack Hits NPM
Feb 24, 2026MediumNewsSecurityIndustryA supply chain attack dubbed 'Sandworm_Mode' has hit NPM. The malicious code spreads like a worm, poisons AI assistants, exfiltrates secrets, and includes a destructive dead switch.
SecurityWeekAutonomous AI Agents Provide New Class of Supply Chain Attack
Feb 23, 2026MediumNewsSecurityIndustryA campaign targets crypto wallets and steals money. The source says its methodology has far wider potential and could be used by other attackers.
SecurityWeekCline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
Feb 20, 2026MediumNewsSecurityIndustryOn February 17, 2026, an unauthorized party used a compromised npm publish token to publish cline@2.3.0 of the Cline CLI, which added a postinstall script that runs npm install -g openclaw@latest. Anyone who installed that version during the roughly eight-hour window from 3:26 a.m. to 11:30 a.m. PT got OpenClaw installed on their machine. Cline says no other changes or malicious behavior were observed.
Fix: To mitigate the unauthorized publication, Cline maintainers released version 2.4.0, deprecated version 2.3.0, and revoked the compromised token. The npm publishing mechanism was updated to support OpenID Connect (OIDC) via GitHub Actions. Users are advised to update to the latest version, check their environment for unexpected installation of OpenClaw, and remove it if not required.
The Hacker NewsMachine Learning Attack Series: Backdooring Pickle Files
Aug 28, 2022MediumNewsSecurityResearchA researcher backdoored a Python pickle file from a two-year-old Husky AI Google Colab notebook using fickling's --inject command. When the file was loaded by StyleGAN2-ADA's generate command, the injected code executed without affecting the program's output. The author notes that Google Drive mapped into Colab projects could expose that data to an attacker who tricks a user into opening a malicious pickle file.
Fix: Fickling's --check-safety command checks pickle files for malicious opcodes and --trace shows the opcodes. The author advises only opening pickle files that you created or trust.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.