Post by Yuchen Jin on X
Yuchen Jin@Yuchenj_UW
XDarn, one of npm’s most widely used packages just got hit by a supply chain attack.
A week ago, it was the LiteLLM Python library.
OpenAI or Anthropic really should consider giving open-source projects free tokens to run the cybersecurity agents on their code.
400 likes33 repliesPosted Mar 31, 2026