When Your Scanner Becomes the Weapon: From Trivy to LiteLLM
ID: 11310d3c-af95-52f9-98a6-6ca32873bb5a
STIX ID: report--11310d3c-af95-52f9-98a6-6ca32873bb5a
Feed Name: Security Boulevard
Threat Score
On March 24, 2026 attackers used credentials exfiltrated from a poisoned Trivy binary in CI to publish malicious LiteLLM PyPI packages (v1.82.7 and v1.82.8) that harvested cloud credentials, Kubernetes secrets, and crypto wallets, persisted via a .pth loader and systemd service, and performed Kubernetes lateral movement; the post provides IOCs, detection/remediation playbooks, and hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
