Linuxgram ๐Ÿง
72.5K subscribers
1.02K photos
5 files
16.9K links
News and info from the Linux world ๐Ÿง
๐Ÿ“จ linuxgr4m@gmail.com ๐Ÿ“จ

๐Ÿ’ธ If you want to support Linuxgramโค๏ธ ๐Ÿง
- BTC: 15aVLQeNY18VAaoBXPgLFA4wfwJnecbjC1
Download Telegram
๐Ÿ“ฐ Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Cybersecurity researchers have discovered a new supply chain attack in which legitimate packages on npm and the Python Package Index (PyPI) repository have been compromised to push malicious versions to facilitate wallet credential theft and remote code execution.The compromised versions of the two packages are listed below -@dydxprotocol/v4-client-js (npm) - 3.4.1, 1.22.1, 1.15.2, 1.0.31&.

๐Ÿ”— Source: https://thehackernews.com/2026/02/compromised-dydx-npm-and-pypi-packages.html

#python
๐Ÿ‘13๐Ÿ˜ฑ8๐Ÿ‘Ž2
๐Ÿ“ฐ Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group.The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry. It's assessed to be active since May 2025.".

๐Ÿ”— Source: https://thehackernews.com/2026/02/lazarus-campaign-plants-malicious.html

#python
๐Ÿ˜ฑ21๐Ÿ’ฉ5๐Ÿ‘3โค1
๐Ÿ“ฐ AMD GAIA 0.16 Introduces C++17 Agent Framework For Building AI PC Agents In Pure C++

AMD's GAIA open-source framework for building AI agents that run locally on Ryzen AI hardware via the Radeon iGPUs and/or NPUs is up to version 0.16. With this new GAIA release is support for developing AI agents purely in C++ with no longer needing to depend upon Python...

๐Ÿ”— Source: https://www.phoronix.com/news/AMD-GAIA-0.16

#amd #opensource #python
๐Ÿ‘14โค10๐Ÿ’ฉ6
๐Ÿ“ฐ LiteLLM loses game of Trivy pursuit, gets compromised

Python interface for LLMs infected with malware via polluted CI/CD pipeline Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential-stealing code.โ€ฆ

๐Ÿ”— Source: https://go.theregister.com/feed/www.theregister.com/2026/03/24/trivy_compromise_litellm/

#python #opensource
๐Ÿ˜ฑ14๐Ÿ’ฉ3
๐Ÿ“ฐ Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig.The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including.

๐Ÿ”— Source: https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html

#opensource #python #security
๐Ÿ˜ฑ15