logo

When Your Scanner Becomes the Weapon: From Trivy to LiteLLM

ID: 11310d3c-af95-52f9-98a6-6ca32873bb5a

STIX ID: report--11310d3c-af95-52f9-98a6-6ca32873bb5a

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Omer Guetta

...
...

On March 24, 2026 attackers used credentials exfiltrated from a poisoned Trivy binary in CI to publish malicious LiteLLM PyPI packages (v1.82.7 and v1.82.8) that harvested cloud credentials, Kubernetes secrets, and crypto wallets, persisted via a .pth loader and systemd service, and performed Kubernetes lateral movement; the post provides IOCs, detection/remediation playbooks, and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.