🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.
The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once.
The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine.
The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had.
That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months.
The attack chain is the part that gets worse every sentence.
TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials.
Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one.
The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions.
TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.”
Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours.
The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
The world is not ready for what AI is about to unlock!
I connected 2 product databases in a few clicks and asked a vague question about some new users.
The agent figured out what I meant, cross-referenced the data, and found the exact users I was looking for.
We’re entering a very different era 🤯
Be honest:
One tool for your entire team’s
data infra + data unification + BI + AI + governance + semantic layer.
Uniform experience for everyone.
Auto-tailored to exactly the data *you* can access.
Would you try it?
Messy CSVs. Broken columns. Random errors.
Most tools stop. Our AI agent fixes itself and keeps going.Inventory runway in seconds. No SQL. No cleanup.
Try it → https://t.co/QiG1rG3T2i
Reply DEMO for the walkthrough.
#AI#Automation#SaaS
We’re doing a live demo of Papermap.
A hands on walkthrough led by Isaac Sarfo and Benedict Quartey.
Real messy data turned into answers using AI.
Jan 23. 2–3 PM EST
Live demo + Q&A on Luma
Register here ⬇️
https://t.co/yLqLwhbBrA
AI isn’t just for Fortune 500s.
Your small business deserves lightning-fast AI, without the price tag.
Papermap AI puts autonomous agents in your hands. Fast. Smart. Affordable.
Ready to level up? [https://t.co/L6DJeHMJ8D]
#LightningAI#AIForEveryone#SmallBizTech #SMBInnovation
The gov may shut down… but with PaperMap AI, your business won’t.
PaperMap AI helps you:
• Spot slowdowns in spending
• See where sales are slowing
• Change plans before sales drop
Because business doesn’t get “out of office.”
#DonaldTrumpsShutdown#SmallBusiness #PaperMapAI #AI