Threats·Cloud & SaaSBreakingMalicious PyPI Package Masquerades as vLLM Process to Exfiltrate Vector Database Weights (GHSA-rghm-9c3j-wc97)A sophisticated typosquatted Python package targets AI engineering pipelines, masquerading as vLLM inference worker daemons to exfiltrate proprietary model weights.CST Newsroom30 Sep 202610 min read