Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially exposed, though the actual number of impacted systems is likely lower. The attack involved a compromised PyPI upload and leveraged a vulnerability in Trivy, leading to the exfiltration of sensitive data, including API keys, SSH keys, and cloud credentials. Organizations are advised to check for LiteLLM installations, rotate compromised secrets, and search for specific repository names associated with the campaign.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
