logo

More supply chain compromises: Namaste, xinference, and more

ID: a9a96397-8279-5782-9d1c-aa1d201e72fd

STIX ID: report--a9a96397-8279-5782-9d1c-aa1d201e72fd

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-27

...
...

Two active supply-chain attacks are compromising npm/PyPI packages and a popular AI model-serving framework to deploy Python backdoors and credential-stealers that harvest AWS/GCP/Azure keys, SSH keys, and Kubernetes secrets; the malware spreads via post-install scripts and by hijacking developer publishing pipelines, and includes IOCs and immediate mitigation advice (rotate credentials, disable post-install scripts, pin dependencies, and reinstall from a clean state).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.