Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption62
- Hype gap+24
- Incentives70
- Confidence66
Unit 42 says the group backdoored Trivy, KICS, LiteLLM and Telnyx's Python SDK, tools that run inside CI with the privileges needed to reach production secrets, which is also why the headline counts deserve a slow read.
Reality
- Evidence55
- Adoption58
- Hype gap+32
- Incentives78
- Confidence48
Datadog's investigation puts genuine PyPI releases of litellm and telnyx inside the same campaign that poisoned Trivy on March 19, which makes the unit of remediation the secrets the build could see rather than the version pin.
Publishers:securitylabs.datadoghq.com
Reality
- Evidence71
- Adoption62
- Hype gap−8
- Incentives58
- Confidence64
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
SOCRadar's record-level data puts 95 percent of identified victims before the poisoned LiteLLM packages ever hit PyPI. Anyone who rotated only what LiteLLM touched is still exposed.
Reality
- Evidence52
- Adoption68
- Hype gap+12
- Incentives66
- Confidence55