Building AI Security with Our Customers: 5 Lessons from Evo’s Design Partner Program

2026-04-02T08:52:12Z497f96d6634ce890aca9c439b70c54a707cf9d8f42a037f588f19fdae96193d0
TeamPCPaxiosbackdoorci-cd-compromisecompromised-maintainer-accountcredential-theftgithub-actionsincident-responselitellmlockfilemalicious-packagenpmpypiremote-access-trojansbomsnyk-reportsoftware-supply-chainsupply-chain-attackthree-stage-malwaretrivy

What happened

Snyk reported multiple high‑risk software supply‑chain compromises: malicious Axios npm releases (1.14.1 and 0.30.4) were published from a compromised maintainer account and injected a hidden dependency that deploys a cross‑platform remote‑access trojan (RAT); separately, actor TeamPCP backdoored litellm Python package releases after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD, delivering a three‑stage malware chain. Both incidents enable remote access/backdoor persistence and potential credential/exfiltration exposure. Recommended actions: identify use (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
497f96d6634ce890aca9c439b70c54a707cf9d8f42a037f588f19fdae96193d0
Enrichment time
2026-04-02T08:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.