Trivy Scan Exposes 2,500 Orgs, Not LiteLLM Exploit
TL;DR. A cybersecurity firm reports that over 95% of organizations affected in a recent supply chain compromise were exposed by the Trivy scanner, not LiteLLM. - The compromise originated from TeamPCP and involved the Shai-Hulud worm affecting open source software. - Malicious code harvested credentials and API keys, then spread by modifying accessible packages with stolen developer secrets. - The LiteLLM packages were only vulnerable for about 40 minutes, indicating a broader Trivy-related issue.
- Most of the 2,500 organizations affected in a recent supply chain attack were compromised via the Trivy security scanner, not LiteLLM.
- The malicious activity began earlier, affecting Trivy users before the LiteLLM packages were compromised.
- TeamPCP is identified as the threat actor, utilizing the Shai-Hulud worm to propagate malware through open-source software.
- The attack method involved automatic execution of malicious code to steal credentials and API keys, then spreading through modified packages.
Sources
- Trivy, Not LiteLLM Behind the 2,500 Org Compromise — securityweek.com