<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #malware</title><description>Articles tagged malware on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies</title><link>https://devtake.dev/article/gpt-proxy-npm-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/gpt-proxy-npm-supply-chain/</guid><description>Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.</description><pubDate>Sat, 25 Apr 2026 07:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>ai-security</category><category>malware</category><category>llm</category><category>china</category><category>credential-theft</category><author>editorial-team</author></item></channel></rss>