As cited
Citation snapshot as of .
breaches incidents
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM packages on PyPI in March contained credential-stealing code and remained available for approximately 40 minutes, targeting systems to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. CloudSEK obtained a dataset of roughly 434,000 captured files from the attack that maps exposure to potentially 2,100 or more organizations.
Why it matters: Organizations that installed LiteLLM from PyPI during the compromise window face exposure of critical credentials and authentication tokens; practitioners should audit deployments immediately and rotate any secrets that may have been harvested.
- Source published
- First seen by Cybersecurity Tracker