Malicious LiteLLM Releases Linked to Trivy Supply Chain Attack May Have Exposed Thousands of Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systemโ€ฆ. The compromise of a widely used developer tool like LiteLLM highlights the pervasive supply chain risks in the software development ecosystem.

https://meta-news.info/veโ€ฆ