Another npm supply chain worm is tearing through dev environments

2026-04-23T07:23:58Z97754002933d88fae441ef7d18f018d6361d4dfa6686c372214d0f38c163363b
active-exploitationapache-activemqcisacisco-sd-wandata-breachlitellmmacos-infostealernpmoauth-abuseransomwaresecrets-theftsupply-chainteampcpvercelworm

What happened

Multiple active and emerging threats reported: a new npm supply‑chain 'worm' is propagating through developer environments to steal secrets and sensitive data (payload references 'TeamPCP/LiteLLM'), while several other incidents show active exploitation and data theft. Notable items include a Vercel breach tied to OAuth abuse and a compromised employee account (Context.ai implicated), Cisco Catalyst SD‑WAN Manager vulnerabilities under active attack with an urgent CISA advisory, a newly‑exploited long‑standing Apache ActiveMQ bug placed on KEV, a macOS ClickFix AppleScript infostealer exfiltr‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
97754002933d88fae441ef7d18f018d6361d4dfa6686c372214d0f38c163363b
Enrichment time
2026-04-23T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.