<h1 align="center">
<a href="https://prompts.chat">
**Status:** Active. Package quarantined on PyPI. Tracking issue: [#1473](https://github.com/guardrails-ai/guardrails/issues/1473).
Loading actions...
<a href="https://prompts.chat">
TypeScript and ESLint rules that MUST be followed when creating, modifying, or reviewing any file under apps/frontend/, including .ts, .tsx, .js, and .jsx files. Also apply when discussing frontend linting, type safety, or ESLint configuration.
risks
Status: Active. Package quarantined on PyPI. Tracking issue: #1473.
Affected version: guardrails-ai==0.10.1 on PyPI
Safe version: guardrails-ai==0.10.0 and earlier
Severity: Critical
Published: May 12, 2026
Last updated: May 12, 2026
On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of guardrails-ai (0.10.1) to PyPI. This compromise was part of a broader supply chain campaign affecting multiple open source packages during the same timeframe. Security researchers identified the malicious package within approximately 2 hours, and PyPI quarantined the repository.
Based on our telemetry, we have observed no requests to Guardrails AI infrastructure originating from the malicious 0.10.1 version, and a review of system and access logs has produced no evidence of user data exfiltration through our systems.
If you installed guardrails-ai==0.10.1 from PyPI on May 11, 2026, your local environment may be compromised. See What you need to do below.
guardrails-ai==0.10.1The package is quarantined on PyPI, but pin explicitly to be safe:
guardrails-ai==0.10.0
pip install git+https://github.com/guardrails-ai/[email protected]
The v0.10.0 tag in this repository is clean. We will update this advisory when the quarantine is lifted and a safe replacement is available on PyPI.
pip uninstall guardrails-aiAll Snowglobe API keys will be invalidated at 2:00 PM Pacific, May 13, 2026. Rotate yours before then to avoid service interruption. We have no evidence Snowglobe or Guardrails Hub keys were exposed; we are rotating proactively.
guardrails-ai organization that produced artifacts containing repository secrets.guardrails-ai==0.10.1 to PyPI.The attacker also unsuccessfully attempted to: