AI expert Andrej Karpathy exposes a supply chain attack on Python library litellm, with nearly 100 million monthly downloads. Malicious code infiltrates via disguised updates, impacting the AI toolchain, raising concerns over open-source software security.....
OpenClaw AI framework faces supply chain attack via ClawHub, where malicious software disguised as tools spreads through community-developed 'skills'.....
Cybersecurity researchers warn of a new software supply chain attack called "Slopsquatting." This attack exploits the 'package hallucination' phenomenon – where generative AI (like LLMs) may suggest non-existent package names during code writing. Attackers can preemptively register these fictitious names and inject malicious code. Image Note: Image generated by AI, courtesy of Midjourney. Research reveals that AI-fabricated package names often exhibit a high degree of...
Xai
$1.4
Input tokens/M
$10.5
Output tokens/M
256
Context Length
Anthropic
$105
$525
200
AI package security scanning tool, offering two modes: CLI and MCP server. It can quickly detect vulnerabilities, prompt injection, and supply chain attacks in MCP servers, AI skills, and software packages.
BoostSecurity MCP is a security tool for protecting the AI agent development workflow. It prevents supply chain attacks by verifying the security of third - party software packages and supports multiple programming languages and package ecosystems.