Slopsquatting campaign on npm
126 malicious npm packages exploited AI-hallucinated package names.
LiteLLM · 2026-03
A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.
The sources report a breach of a 10 billion dollar AI startup.
The route in was the LiteLLM supply-chain attack.
The claim is 4 TB stolen.
Supply chain
Where a dependency came from is not visible from a public URL. Provenance belongs in the Release Gate checklist.
126 malicious npm packages exploited AI-hallucinated package names.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026