Cybersecurity6 min reading time
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
The Hacker News
Read full postTwo malicious versions of LiteLLM were briefly available on PyPI in March, containing code that stole various credentials from systems that installed them. CloudSEK analyzed captured data suggesting potential exposure of secrets from over 2,500 organizations, including major companies, though actual misuse is unconfirmed. Users are advised to rotate credentials to mitigate risks from this incident.



