The **GitSpawn AI supply chain attack has officially reached Indian developers**, with malicious code injected into popular open-source AI agent packages distributed via public registries. Security researchers report that **over 12,000 downloads originated from India**, making it a primary target zone—primarily hitting CI/CD pipelines and automated code-review bots.
⚡ Fast Takeaways:
- Core Update: Compromised packages mimic real AI coding assistants like GitSpawn-CLI and auto-merge-bot; malicious payload activates post-install and exfiltrates cloud credentials and SSH keys.
- Key Metrics / Specs: Attackers used typosquatting with 98% code similarity to legitimate versions. 4 malicious versions were live for 6+ days before being pulled, impacting an estimated 40,000+ repos globally.
- Access & Availability: Immediate action required—audit package locks, rotate all stored tokens, and monitor for unexpected outbound traffic to suspicious IP ranges before resuming normal deployment.