AI supply-chain attacks bypass model red teams

TL;DR AI
2 min readKey summary
Over 50 days, four incidents hit AI companies and nearby infrastructure across npm, PyPI, GitHub Actions, and public release assets.
A self-spreading npm worm hit TanStack releases, OpenAI reported stolen employee-device and repo credentials, and LiteLLM packages were poisoned with stolen tokens, affecting Mercor.
OpenAI Codex also had a command-injection flaw, while Anthropic accidentally exposed Claude Code source code through a public source map.
The common issue is supply-chain and release-pipeline security, showing that model red-teaming does not cover token theft, dependency poisoning, or source leaks.
