Topic: open source compromise
-
Open source package with 1M monthly downloads stole user credentials
Attackers exploited a vulnerability in a GitHub action workflow to hijack the open-source package "element-data", downloaded over 1 million times monthly, stealing signing keys and credentials to release a malicious version. The tampered package, tagged 0.23.3, scanned environments for sensitiv...
Read More » -
Meta Halts AI Training After Data Breach
A sophisticated supply chain attack, executed via a compromised open-source tool (LiteLLM), has led Meta to indefinitely suspend its partnership with data startup Mercor and exposed vast personal data alongside potentially proprietary AI training methodologies. The breach, which compromised four ...
Read More » -
Mercor Cyberattack Linked to Compromised LiteLLM Project
The AI recruiting platform Mercor was compromised in a supply chain attack linked to the open-source project LiteLLM, with the extortion group Lapsus$ also claiming to have targeted and accessed its data. Mercor, a high-value startup facilitating over $2 million in daily payouts, is investigating...
Read More »