supply-chain
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
High
Summary
Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner, allowing threat actors (TeamPCP) to inject malicious code into LiteLLM, leading to widespread exposure of sensitive data including credentials, keys, and tokens. The incident highlights the increasing risk of AI infrastructure as a critical attack vector.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data