Home / Aug 13, 2026 / Story
0
#3 The Hacker News general August 12, 2026 at 08:04 UTC

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

By [email protected] (The Hacker News)

AI Summary

Two malicious LiteLLM releases were pushed to PyPI in March 2026 via the Trivy supply chain hack, remaining available for approximately 40 minutes before removal — yet credential-stealing code captured data from 434,000 files across 2,100+ organizations. Stolen data included cloud API keys, SSH keys, Kubernetes tokens, and database passwords, making this one of the most impactful AI-toolchain supply chain attacks to date.

Relevance score: 89.0/100

# More from August 13