National Cybersecurity Incident Response Center: Multiple incidents of supply chain poisoning attacks have recently occurred, involving two major core supply chain scenarios.

date
10/04/2026
According to the National Cyber Security Notification Center, the National Notification Center has monitored and discovered multiple supply chain poisoning attacks that have recently occurred, targeting API development tool Apifox, Python development library LiteLLM, and JavaScript HTTP library Axios. These attacks involve both open source software repositories and commercial tool supply chain scenarios. Among them, the Axios poisoning incident has a significant impact as many AI applications and plugin ecosystems such as OpenClaw directly rely on this library, causing risks to further spread to end users through dependency chains. These three supply chain poisoning incidents exhibit common characteristics of strong stealthiness of attack, wide impact range, high degree of harm, and fast propagation speed, which can result in serious consequences such as stolen credentials, remote code execution, and sensitive data leakage.
Latest
See all latestmore