LiteLLM loses game of Trivy pursuit, gets compromised
2026-03-24T19:23:59Z•3b2878a62cefbbed7687255448b65d235dd24cf918733bb41c2f26d30a3cb230
CI/CDLiteLLMPyPIPythonTrivycredential-stealerdependency-compromisemalwaresoftware-supply-chainsupply-chainthird-party-risk
What happened
Two compromised LiteLLM Python packages were removed from PyPI after a supply‑chain attack injected credential‑stealing malware into the project via a polluted CI/CD pipeline. The malicious code was distributed in released package versions, exposing users who installed those releases to credential theft and other post‑install malicious activity. PyPI takedown is in place; affected users should assume compromise of any environments that installed the malicious versions, rotate credentials and secrets, audit build pipelines and CI artifacts, pin/verifiably source dependencies, and scan for the I
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 3b2878a62cefbbed7687255448b65d235dd24cf918733bb41c2f26d30a3cb230
- Enrichment time
- 2026-03-24T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.