Home / Aug 14, 2026 / Story
0
#5 SecurityWeek general August 12, 2026 at 09:55 UTC

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

By Ionut Arghire

AI Summary

A supply chain attack on LiteLLM — carried out via a compromise of the Trivy security scanning tool — resulted in information-stealing malware being distributed to over 2,500 organizations using the popular AI gateway library. Terabytes of credentials were reportedly scraped and exfiltrated from affected users. Security teams using LiteLLM or Trivy in CI/CD pipelines should audit dependencies and rotate any credentials that may have been exposed.

Relevance score: 87.0/100

# More from August 14