Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Read full story on The Hacker News
Share
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
AI disclosure

Summary

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.