Back to all news
Security

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The Hacker News·August 12, 2026·1 min read
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases on PyPI carried credential-stealing code for about 40 minutes in March, harvesting cloud keys, SSH keys, Kubernetes tokens, and database passwords. Threat intelligence firm CloudSEK obtained a dataset of roughly 434,000 captured files, mapping potential exposure to over 2,100 organizations.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store