[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp4HXULub3BKiFDHkxl8S4hyQ8x526FvlpDElUUbFxgU":3},{"article":4,"iocs":52,"watch_terms":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":36},"c9cf1d73-f3b1-43cf-8aec-aac58ea3a8ec","Silverfort + SentinelOne: Securing Identities in the AI Era\n\nOn March 31, 2026, a North Korean st...","silverfort-sentinelone-securing-identities-in-the-ai-era-on-march-31-2026-a-nort-922d61","Silverfort + SentinelOne: Securing Identities in the AI Era\n\nOn March 31, 2026, a North Korean state actor executed a supply chain attack where the first infection was observed just 89 seconds after publication. Last week, SentinelOne caught a trojaned version of LiteLLM updated https:\u002F\u002Ft.co\u002F4xxHjzzppm","On March 31, 2026, a North Korean state-sponsored actor executed a supply chain attack by compromising the LiteLLM package, with the first malicious infection detected just 89 seconds after the trojaned version was published. SentinelOne identified the compromised package as part of an apparent coordinated campaign targeting organizations relying on the popular LLM proxy library. The rapid exploitation suggests reconnaissance and automation of infection chains.","North Korean actor exploits trojaned LiteLLM package in supply chain attack detected within 89 seconds of release.",null,"https:\u002F\u002Fx.com\u002FSentinelOne\u002Fstatus\u002F2046578547955793995","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGboU3kWsAA1tp-.jpg","2026-04-21T13:15:24+00:00","2026-04-21T14:00:08.073879+00:00",9,[18,21,24,27,29],{"name":19,"type":20},"North Korean state actor","threat_actor",{"name":22,"type":23},"SentinelOne","vendor",{"name":25,"type":26},"LiteLLM","product",{"name":28,"type":23},"Silverfort",{"name":30,"type":31},"Python package management","technology","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":32,"icon":11,"name":34,"slug":35},"Supply Chain","supply-chain",[37,42,47],{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":49,"icon":11,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":46,"value":54,"context":55},"trojaned LiteLLM","Compromised Python package used for LLM proxy; part of North Korean supply chain attack on March 31, 2026",[22,28,25]]