Code trust crisis: Is it safe to update your system during an active supply chain attack?

Running a routine Python pip update command on March 24 could’ve pulled malware that stole passwords and crypto savings. Running npm update a week later could’ve dropped a trojan. Critical LiteLLM and axios attacks expose just how vulnerable dependency trees are. But can you get infected just by running OS update commands like β€œapt update,” β€œdnf upgrade,” or β€œbrew upgrade?”

Read more at Cyber News.

Code trust crisis: Is it safe to update your system during an active supply chain attack? - Newsroom Cybernews

About Mend.io

Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerβ€”and the interactions between them, where modern application risk now livesβ€”Mend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.