The JFrog security research team identified a supply chain attack on the `xinference` package on PyPI, affecting versions 2.6.0, 2.6.1, and 2.6.2.
These versions were pulled after reports of suspicious activity, and users who installed them should assume their systems are compromised. Additionally, a GitHub repository published numerous SQLite vulnerability advisories, which NVD and CISA's ADP initially flagged as critical.