logo

AppSec as attacker: Inside Trivy–LiteLLM

ID: b29bde06-89fb-533f-9a04-7ff8ac96cecd

STIX ID: report--b29bde06-89fb-533f-9a04-7ff8ac96cecd

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-05-01

Author: Igor Lasic

...
...

TeamPCP conducted a sophisticated supply-chain attack by compromising the Trivy GitHub Action and injecting .pth-based malware that ran at Python startup to scrape and exfiltrate cloud credentials and secrets; stolen tokens were then used to backdoor LiteLLM on PyPI, potentially impacting millions of AI deployments and high-value API keys. The report explains the technical delivery (.pth files), the stealth and detection gaps, and provides immediate mitigations (pin actions by SHA, audit .pth files, rotate CI/CD secrets, add behavioral ML scanning, and implement egress monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.