#3
The Hacker News
general
August 12, 2026 at 08:04 UTC
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
By [email protected] (The Hacker News)
AI Summary
Two malicious LiteLLM releases were pushed to PyPI in March 2026 via the Trivy supply chain hack, remaining available for approximately 40 minutes before removal — yet credential-stealing code captured data from 434,000 files across 2,100+ organizations. Stolen data included cloud API keys, SSH keys, Kubernetes tokens, and database passwords, making this one of the most impactful AI-toolchain supply chain attacks to date.
Relevance score: 89.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →