SECURITYTHE HACKER NEWS
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases were found on PyPI for about 40 minutes, containing code designed to steal credentials such as cloud keys, SSH keys, and database passwords from installed systems. A threat intelligence firm, CloudSEK, obtained a dataset built from approximately 434,000 captured files, which maps potential exposure to over 2,100 organizations.
Mentioned
Related Signal
Adjacent reporting
- Massive supply-chain attack compromises 440 packages under four hours
- Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
- ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack