Supply Chain Attack Compromises Python AI/ML Libraries — 45M Downloads
Three popular Python AI/ML packages on PyPI compromised. Credential-stealing code targets AWS, GCP, Azure, and AI API keys.
CVE-2026-31001CVE-2026-31002PyPI ecosystem
JFrog Security Research