CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4283

As cited

Citation snapshot as of .

breaches incidents

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM packages on PyPI in March contained credential-stealing code and remained available for approximately 40 minutes, targeting systems to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. CloudSEK obtained a dataset of roughly 434,000 captured files from the attack that maps exposure to potentially 2,100 or more organizations.

Why it matters: Organizations that installed LiteLLM from PyPI during the compromise window face exposure of critical credentials and authentication tokens; practitioners should audit deployments immediately and rotate any secrets that may have been harvested.

Source published
First seen by Cybersecurity Tracker

Source attribution