LiteLLM supply chain compromise
ID: 32da45cb-5902-55fb-a4eb-ec589a122f7c
STIX ID: report--32da45cb-5902-55fb-a4eb-ec589a122f7c
Feed Name: Giskard
TeamPCP compromised the Trivy CI/CD scanner to scrape secrets from CI runners, then used stolen credentials to publish malicious LiteLLM releases (1.82.7 and 1.82.8) to PyPI that exfiltrated secrets; PyPI quarantined and removed the compromised packages. Giskard reports no impact to its commercial customers (they pinned safe versions) but warns open-source users who installed or upgraded during the affected window may be compromised, provides IOCs and a detection script, and outlines fixes and supply-chain hardening steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
