https://reddit.com/r/cybersecurity/comments/1tkfk0l/14_npmpypiai_supplychain_threats_today_20260522/: 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
Published May 22, 2026
·Updated
Affected Software
16 affected components
npm/@cap-js/sqlite<2.4.0
npm/@cap-js/postgres<2.3.0
npm/@cap-js/db-service<2.11.0
npm/@beproduct/nestjs-auth>=0.1.2<=0.1.19
pypi/guardrails-ai=0.10.1
npm/penpot-mcp-repl
pypi/diffusers
pypi/lmdeploy
npm/@libp2p/gossipsub
npm/@libp2p/kad-dht
pypi/crawlee
SillyTavern
npm/samlify
npm/js-cookie
pypi/sqlfluff
pypi/pymdownx.snippets
Frequently Asked Questions
1
What is the severity of CVE-2026-46421?
CVE-2026-46421 is classified as critical due to its potential for credential harvesting and self-propagation.
2
How do I fix CVE-2026-46421?
To fix CVE-2026-46421, update the affected npm packages to their latest secure versions as per the vendor's release notes.
3
What type of attack is associated with CVE-2026-46421?
CVE-2026-46421 is associated with credential harvesting and self-propagation attacks that exploit vulnerabilities in certain npm packages.
4
Which ecosystems are affected by CVE-2026-46421?
CVE-2026-46421 affects the npm ecosystem specifically impacting packages like @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service.
5
What should I do if I suspect exploitation of CVE-2026-46421?
If you suspect exploitation of CVE-2026-46421, immediately audit affected systems, revoke compromised credentials, and apply the necessary updates.