< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-08-12T13:34:52+05:30

Malicious LiteLLM Packages Linked to Trivy Supply-Chain Attack Expose 2,100+ Organizations

Malicious LiteLLM packages containing credential-stealing code were published on PyPI for 40 minutes, potentially exposing 2,100+ organizations through compromised cloud credentials and secrets. The attack is linked to the TeamPCP supply-chain campaign affecting Trivy, with recommendations to rotate CI/CD and cloud credentials immediately.

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.

Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Read original article

*** END OF TRANSMISSION ***