msb ๐ ๐ค
2026-08-12 18:16 ๐ซ๐ฎ
Malicious LiteLLM Releases Linked to Trivy Supply Chain Attack May Have Exposed Thousands of Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systemโฆ. The compromise of a widely used developer tool like LiteLLM highlights the pervasive supply chain risks in the software development ecosystem.
https://meta-news.info/veโฆ
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systemโฆ. The compromise of a widely used developer tool like LiteLLM highlights the pervasive supply chain risks in the software development ecosystem.
https://meta-news.info/veโฆ