Image: The Hacker NewsMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
β’ Malicious versions of the LiteLLM package were released on PyPI, designed to steal cloud and SSH keys, Kubernetes tokens, and other sensitive secrets. β’ The attack is linked to a previous hack of Trivy, potentially exposing more than 2,100 organizations to security breaches. β’ This incident highlights a growing trend of supply chain attacks targeting popular AI-related libraries to gain unauthorized access to corporate infrastructure.
thehackernews.com