Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach

2026-03-30T19:24:02Z2a164d17bb1060463014dd96705ece7777b0ea64a72985626799b35084425b3a
api‑keyscitrix‑netscalercloud‑infectioncredential‑stealerdata‑breacheuropean‑commissionincident‑responsein‑the‑wild‑exploitlitellmpackage‑poisoningpypisoftware‑supply‑chainsupply-chaintelnyxthird‑party‑risktrivy

What happened

Multiple high-impact incidents: the Trivy supply-chain compromise continues to ripple through open-source ecosystems — attackers pushed malicious, credential‑stealing versions of PyPI packages (notably LiteLLM and Telnyx) and researchers report 1,000+ cloud environments infected. Separately, a critical Citrix NetScaler vulnerability is being exploited in the wild within days of disclosure, and the European Commission confirmed a breach of public-facing web systems. Numerous other breaches and exposures were reported (AFC Ajax, third‑party supplier data, widespread API keys in website code), as

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
2a164d17bb1060463014dd96705ece7777b0ea64a72985626799b35084425b3a
Enrichment time
2026-03-30T19:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach · Baitaphish