Tag: supply-chain
All the articles with the tag "supply-chain".
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
Weekly Roundup: Poisoned Skills, Booby-Trapped AGENTS.md and 19,000 Wiretapped Firewalls
Eleven posts this window, four of them about agents reading text somebody else controlled. Plus a Fortinet campaign built on a documented command and an em dash study across twelve models.
-
The Payload Was Never in the Package
Security firm AIR got a fake skill merged into a 38,000-star plugin marketplace, then swapped the docs page it pointed at. Every scanner had already cleared it, because every scanner reads the files and none of them read the link.
-
One Maintainer's Prompt Injection Insults You. Another's Deletes Your Tests.
Mitchell Hashimoto's booby-trapped AGENTS.md has been sitting in Ghostty since February, and he says it catches unreviewed AI PRs all the time. It's about as harmless as this technique gets. jqwik shipped the destructive version to Maven Central a month ago.