CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4283

As cited

Copy frozen at (site build).

breaches incidents

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM packages on PyPI in March contained credential-stealing code and remained available for approximately 40 minutes, targeting systems to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. CloudSEK obtained a dataset of roughly 434,000 captured files from the attack that maps exposure to potentially 2,100 or more organizations.

Why it matters: Organizations that installed LiteLLM from PyPI during the compromise window face exposure of critical credentials and authentication tokens; practitioners should audit deployments immediately and rotate any secrets that may have been harvested.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM packages on PyPI in March contained credential-stealing code and remained available for approximately 40 minutes, targeting systems to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. CloudSEK obtained a dataset of roughly 434,000 captured files from the attack that maps exposure to potentially 2,100 or more organizations.

Why it matters: Organizations that installed LiteLLM from PyPI during the compromise window face exposure of critical credentials and authentication tokens; practitioners should audit deployments immediately and rotate any secrets that may have been harvested.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary