Skip to content
archivesupply chain · 12 Aug 2026 · 08:04 UTC

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

last 60 dispatches · spectrum

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected