daily
The Signal — April 1, 2026
Three npm supply chain incidents hit in a single 24-hour window on March 31. A compromised maintainer account pushed a remote access trojan through Axios. A separate attack on the LiteLLM AI proxy led to terabytes of corporate data walking out the door. And Anthropic accidentally shipped its own source