20:55
2026-08-18
forkast.news
ai-infrastructure
The Package Registry Layer: How Supply-Chain Attacks Are Targeting Agent Infrastructure
On March 24, 2026, malicious versions of the LiteLLM library (1.82.7 and 1.82.8) were hosted on the Python Package Index (PyPI) for approximately 40 minutes by threat actor Team PCP, exfiltrating 78,3โฆ