Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
The Hacker News reported that malicious releases of LiteLLM, a popular open-source AI gateway, have been tied to a hack of the Trivy vulnerability scanner project. The attack may have exposed more than 2,100 organizations. The malicious releases were distributed through official channels, potentially compromising users who installed them. The report suggests that the attackers leveraged the Trivy hack to inject malicious code into LiteLLM releases, which were then made available to users. The full scope of the exposure is not yet known, but the incident highlights the risks of supply chain attacks in open-source software. The report does not specify which versions of LiteLLM were affected or provide technical details of the attack vector.
Supply chain attacks on popular open-source tools can compromise thousands of organizations, making verification of software integrity critical.