LiteLLM loses game of Trivy pursuit, gets compromised
ID: 8bdce32f-2381-5449-b360-77562f4c186a
STIX ID: report--8bdce32f-2381-5449-b360-77562f4c186a
Feed Name: The Register (Security)
Attackers exploited a misconfiguration in the Trivy GitHub Action to steal CI/CD tokens and publish malicious LiteLLM PyPI packages (v1.82.7 and v1.82.8) that included credential-stealing code in litellm_init.pth; malicious Trivy releases and Docker images were used to propagate the compromise and the project's GitHub vulnerability report was flooded with spam to obscure useful comments. PyPI removed the affected packages and PyPA advises revoking/rotating credentials for anyone who ran the project.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
