Building AI Security with Our Customers: 5 Lessons from Evo’s Design Partner Program
2026-04-02T08:52:12Z•497f96d6634ce890aca9c439b70c54a707cf9d8f42a037f588f19fdae96193d0
TeamPCPaxiosbackdoorci-cd-compromisecompromised-maintainer-accountcredential-theftgithub-actionsincident-responselitellmlockfilemalicious-packagenpmpypiremote-access-trojansbomsnyk-reportsoftware-supply-chainsupply-chain-attackthree-stage-malwaretrivy
What happened
Snyk reported multiple high‑risk software supply‑chain compromises: malicious Axios npm releases (1.14.1 and 0.30.4) were published from a compromised maintainer account and injected a hidden dependency that deploys a cross‑platform remote‑access trojan (RAT); separately, actor TeamPCP backdoored litellm Python package releases after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD, delivering a three‑stage malware chain. Both incidents enable remote access/backdoor persistence and potential credential/exfiltration exposure. Recommended actions: identify use (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- 497f96d6634ce890aca9c439b70c54a707cf9d8f42a037f588f19fdae96193d0
- Enrichment time
- 2026-04-02T08:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.