Mini Shai-Hulud npm worm compromises 160+ packages, including TanStack-related packages

Critical vm2 Sandbox Escape Bugs Allow Host RCE in Node.js Environments

How the TeamPCP attack exploited CI/CD pipelines and trusted releases to release infected Trivy and LiteLLM packages

LiteLLM supply chain attack - complete analysis and what it says about trust in dependencies

Why do so many Linux tools assume systemd