HomeAI

LiteLLM attack hit 2,500 organizations — but most were victims of Trivy

LiteLLM attack hit 2,500 organizations — but most were victims of Trivy

The LiteLLM supply chain attack that made headlines this week may have been overstated — most of the 2,500 organizations believed to be affected were actually compromised through a different incident involving Aqua Security's Trivy scanner, according to a new analysis from SOCRadar.

Earlier this week, CloudSEK and HudsonRock reported that more than 2,500 organizations were likely affected by the LiteLLM compromise. But SOCRadar's investigation into the incident data found that the vast majority of those organizations were victims of the Trivy compromise, not the LiteLLM one. Both attacks are attributed to TeamPCP, a threat actor known for a series of open source software supply chain attacks leveraging the Shai-Hulud worm.

The campaign began with the Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect driven by the malware's worm-like behavior and the automated inclusion of the malicious libraries in more builds.

All the compromises linked to TeamPCP followed a similar pattern: the malicious code was automatically executed when the infected package was fetched and run, harvesting credentials, tokens, API keys, and other secrets. Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface.

This is how LiteLLM was compromised. Two poisoned package versions were published on March 24 and remained online for roughly 40 minutes. They were injected with a .pth file that Python automatically executed at interpreter startup, even if LiteLLM was never imported — bypassing ignore-scripts protections.

According to SOCRadar, a close examination of the LiteLLM incident data revealed per-organization records for 2,18 entries, allowing the researchers to distinguish between those affected by the Trivy compromise and those affected by the LiteLLM attack itself. The full breakdown shows that the majority of the 2,500 organizations had already been exposed through the earlier Trivy incident.

Tags: AI
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate