Two LiteLLM releases yanked from PyPI after hackers hijacked Trivy to steal tokens and inject malware. Open source's dirty secret: your trusted tools might be the weakest link.
theAIcatchupApr 07, 20264 min read
⚡ Key Takeaways
LiteLLM v1.82.7/1.82.8 contained credential-stealing malware from Trivy supply chain attack.𝕏
Attackers modified Trivy version tags to inject code into existing CI/CD pipelines.𝕏
Rotate all credentials immediately if you used affected versions; pin commits, not tags, for safety.𝕏
The 60-Second TL;DR
LiteLLM v1.82.7/1.82.8 contained credential-stealing malware from Trivy supply chain attack.
Attackers modified Trivy version tags to inject code into existing CI/CD pipelines.
Rotate all credentials immediately if you used affected versions; pin commits, not tags, for safety.