CircleCI is a technology platform tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed March 25, 2026; most recent activity July 19, 2026.
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A supply chain attack named SleeperGem has been identified targeting the RubyGems ecosystem, exploiting dormant maintainer accounts to publish a malicious gem called git_credential_manager. This gem, which has already…
Braintrust, an AI evaluation startup, confirmed a breach involving unauthorized access to one of its AWS accounts, which contained API keys used by customers for accessing cloud-based AI models. The company notified…