Story thread · 2 reports / 2 sources

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

thehackernews.com · 4h · first report

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

The coverage

  1. Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    securityweek.com · 2h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.