news.mlab.sh
Back to the feed
supply-chain

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

High
Summary

A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vulnerabilities to inject malicious code into packages and steal sensitive information like credentials and API keys. The initial compromise occurred before the malicious packages were published, with the attack’s final stage lasting only 40 minutes as PyPI quarantined the affected files. The stolen data is now being offered for sale on Telegram.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.