Supply Chain Security Crisis Peaks
The ChainDrop worm hijacked keyv, a package with roughly 150M weekly downloads, while retaining valid SLSA provenance and using Ethereum C2 plus persistence in Claude Code and VS Code. Mythos 5's autonomous attack attempt, malicious AI-tool repositories, Gemini CLI's CVSS 10.0 vulnerability, and Claude Code key leaks compound the crisis; GitHub has shipped nine controls, but network firewall protection remains in preview.
Sources (2)
Updated Aug 29, 2026