supply-chain
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
High
Summary
A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vulnerabilities to inject malicious code into packages and steal sensitive information like credentials and API keys. The initial compromise occurred before the malicious packages were published, with the attack’s final stage lasting only 40 minutes as PyPI quarantined the affected files. The stolen data is now being offered for sale on Telegram.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data