Breaches  › Tech  › Malicious LiteLLM Releases Tied to Trivy Hack May…
medium · tech · Disclosed Aug 12, 2026

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems

Original Disclosure
https://thehackernews.com/2026/08/malicious-litellm-release…
Read original
Severity
medium
Sector
tech
Disclosure date
August 12, 2026
Indexed
5 hours, 39 minutes ago