Multiple open source supply chain compromises (March 2026)
Issue
- Beginning in March 2026, multiple widely-used open source projects were impacted by supply chain attacks
Environment
- Any environment using the affected project, such as BerriAI LiteLLM, Aqua Security Trivy, Checkmarx GitHub Actions, Telnyx, Axios, and various npm packages
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.