Another npm supply chain worm is tearing through dev environments
2026-04-23T07:23:58Z•97754002933d88fae441ef7d18f018d6361d4dfa6686c372214d0f38c163363b
active-exploitationapache-activemqcisacisco-sd-wandata-breachlitellmmacos-infostealernpmoauth-abuseransomwaresecrets-theftsupply-chainteampcpvercelworm
What happened
Multiple active and emerging threats reported: a new npm supply‑chain 'worm' is propagating through developer environments to steal secrets and sensitive data (payload references 'TeamPCP/LiteLLM'), while several other incidents show active exploitation and data theft. Notable items include a Vercel breach tied to OAuth abuse and a compromised employee account (Context.ai implicated), Cisco Catalyst SD‑WAN Manager vulnerabilities under active attack with an urgent CISA advisory, a newly‑exploited long‑standing Apache ActiveMQ bug placed on KEV, a macOS ClickFix AppleScript infostealer exfiltr‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 97754002933d88fae441ef7d18f018d6361d4dfa6686c372214d0f38c163363b
- Enrichment time
- 2026-04-23T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.