Code trust crisis: Is it safe to update your system during an active supply chain attack?
Running a routine Python pip update command on March 24 couldβve pulled malware that stole passwords and crypto savings. Running npm update a week later could’ve dropped a trojan. Critical LiteLLM and axios attacks expose just how vulnerable dependency trees are. But can you get infected just by running OS update commands like βapt update,β βdnf upgrade,β or βbrew upgrade?β
Read more at Cyber News.
About Mend.io
Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerβand the interactions between them, where modern application risk now livesβMend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.