Security researchers at Checkmarx Zero have identified a malware campaign that circumvents npm's recent crackdown on lifecycle scripts, one of the package manager's key defensive measures against supply chain attacks. npm (short for Node Package Manager) is the default package manager for the Node.js JavaScript runtime environment. It helps developers install, share, and manage reusable code libraries (called packages) in their projects. The discovery signals that attackers are adapting quickl
oss (2)
A cybersecurity analysis by CloudSEK revealed the scale of the March 2026 LiteLLM supply-chain attack, which exposed about 434,000 CI/CD pipelines at more than 2,500 companies worldwide. Continuous Integration (CI) and Continuous Delivery (CD) pipelines are automated workflows that build, test, and deploy software from a developer’s environment to production users. Although the malicious packages were active for only about 40 minutes, the breach may have exposed critical credentials and securi