Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Trivy, Not LiteLLM Behind the 2,500 Org Compromise
SOCRadar says most of the 2,500 organizations initially linked to the LiteLLM incident were actually exposed earlier through the TeamPCP-led Trivy compromise, which spread downstream across packages and CI/CD systems. The attack used a worm-like payload to steal credentials and secrets, and the collected data is now being brokered on Telegram. #TeamPCP #LiteLLM #Trivy #ShaiHulud #CanisterWorm

Keypoints

  • Most affected organizations were exposed before the LiteLLM package was poisoned.
  • TeamPCP was blamed for the supply chain compromise tied to the Shai-Hulud worm.
  • The attack spread from Aqua Security’s Trivy into downstream packages and repositories.
  • The malware stole JWTs, auth tokens, API keys, private keys, and other secrets.
  • More than 1,100 organizations had committer email addresses exposed, and the stolen data is being sold on Telegram.

Read More: https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/