The LiteLLM Chain Reaction — From Trivy to PyPI, a Textbook AI Supply-Chain Meltdown

TeamPCP compromised Aqua Security's Trivy CI/CD to plant a three-stage payload in LiteLLM 1.82.7–1.82.8. The supply-chain attack exposed API keys and cloud credentials by targeting the tooling layer that connects AI models to applications.

33,000 Agent PRs Tell a Brutal Story: Codex Dominates, Copilot Struggles, and Your Monorepo Might Not Survive

Drexel/Missouri S&T analyzed 33,596 agent-authored GitHub PRs from 5 coding agents. Overall merge rate: 71%. Codex: 83%, Claude Code: 59%, Copilot: 43%. Rejection cause: no review. LeadDev warns PR flood is crushing monorepos/CI.