Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Global marine protected areas fail to safeguard most sharks and rays: Study

    August 14, 2026

    $51 billion LNG megaproject takes ‘important’ step on path to FID by year-end

    August 14, 2026

    New records reveal efforts by North Carolina auditor’s office to sway county early voting decisions

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Global marine protected areas fail to safeguard most sharks and rays: Study
    • $51 billion LNG megaproject takes ‘important’ step on path to FID by year-end
    • New records reveal efforts by North Carolina auditor’s office to sway county early voting decisions
    • At a loss as to which Stephen Moss you’re referring to? So are many others | The Guardian
    • Edited image of Andy Burnham in ‘Free Palestine’ shirt being shared on Facebook – Full Fact
    • As Europe Gets Hotter, Its Transportation Systems Struggle to Cope
    • Russell Fry Backs Darline Graham in South Carolina Senate Runoff Amid Trump Pressure
    • Donald Trump can’t beat Iran and Nigel Farage can only beat a bin. When it counts, these populists are just losers | Jonathan Freedland
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Most of the 2,500 organizations believed to have been affected by the LiteLLM supply chain attack were actually exposed before, SOCRadar reports.

    The compromise was blamed on and claimed by TeamPCP, the threat actor behind multiple open source software (OSS) supply chain attacks involving the Shai-Hulud worm.

    It started with Aqua Security’s Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by the automated inclusion of the malicious libraries in more builds.

    More than 2,500 organizations were likely affected by the LiteLLM attack, CloudSEK and HudsonRock said earlier this week. According to SOCRadar, most of them were victims of the Trivy compromise, not LiteLLM.

    All the compromises associated with TeamPCP followed a similar pattern: malicious code was automatically executed when the infected package was fetched and run to harvest credentials, tokens, API keys, and other secrets.

    Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface.

    Advertisement. Scroll to continue reading.

    This is how LiteLLM was compromised and how two poisoned package versions were published on March 24 and stayed online for roughly 40 minutes.

    They were injected with a .pth file that Python automatically executed at interpreter startup, even if LiteLLM was never imported, bypassing ignore-scripts protections.

    The compromise timeframe

    According to SOCRadar, a close examination of the LiteLLM incident data revealed per-organization records for 2,188 entities, including timestamps, credential types, CI/CD platforms, and domains.

    “Every record carries first-seen and last-seen timestamps. The earliest is March 19 at 18:05 UTC and the latest is March 24 at 20:09 UTC, a span of just over five days,” the cybersecurity firm notes.

    For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry.

    “That timing lines up with the upstream Trivy compromise rather than the LiteLLM install window. The 40 minutes everyone reported was the closing act, not the whole play,” SOCRadar says.

    The earliest collection occurred 18 minutes after the malicious Trivy build was published on March 19. The activity surged on March 22 and March 23 when malicious Trivy images were live on Docker Hub, and closed on March 24 after PyPI quarantined the packages.

    “[This] is what persistence on already-infected hosts looks like: the .pth payload kept running after the source of the infection was gone,” SOCRadar notes.

    The compromise involved six CI/CD platforms, namely GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite, and impacted organizations worldwide, with Germany, Brazil, and France affected the most.

    Stolen, now brokered secrets

    The malware targeted secrets broadly, but over 1,000 organizations exposed JWT and auth tokens. Hundreds of them exposed private keys, AWS access keys, GitLab tokens, OpenAI API keys, Slack webhooks, GitHub Actions tokens, and Google API keys.

    “The highest secret count in the set is roughly 3,477 [the organization has not been named], followed by roughly 3,459. Several high-secret rows rest on very few files or repositories. One row carries 3,459 secrets across just six files,” SOCRadar notes.

    The cybersecurity firm also points out that committer email addresses were compromised across over 1,100 organizations. In those cases, the attackers have both developer identities and machine tokens.

    “Of the 2,188 organizations in the record-level set, 56% are rated high confidence, 39% medium, and 6% low, with figures rounded. Headline reporting cites 2,500+ organizations; the difference reflects which records carry attributable identifiers,” SOCRadar notes.

    “High-confidence matches are keyed on CI host identity and legitimate committer domains, meaning whose systems a captured file came from, rather than any observed use of a stolen credential. These are exposure figures rather than confirmed compromises, drawn from a reconstructed sample rather than a complete census,” it continues.

    The stolen information is already being brokered. One threat actor is offering on Telegram a collection of LiteLLM, Trivy, and CanisterWorm data, likely compiled at various stages of the campaign.

    Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

    Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

    Related: Hackers Exploiting Unpatched GeoServer Zero-Day

    compromise LiteLLM Org Trivy
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    What Boards Need to Know About Tech Risk

    Shell investigates ‘potential incident’ after Clop data theft claims

    In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

    Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

    Data analyst sent to prison for stealing data, extorting employer

    How to reduce cybersecurity backlogs and fix vulnerability debt

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Global marine protected areas fail to safeguard most sharks and rays: Study

    August 14, 2026

    $51 billion LNG megaproject takes ‘important’ step on path to FID by year-end

    August 14, 2026

    New records reveal efforts by North Carolina auditor’s office to sway county early voting decisions

    August 14, 2026

    At a loss as to which Stephen Moss you’re referring to? So are many others | The Guardian

    August 14, 2026
    Latest Posts

    Meta just created a moderation nightmare for its smart glasses

    July 26, 2026

    Maga’s creepy baby obsession won’t solve the fertility crisis

    July 26, 2026

    France battles fire ‘whirlwinds’ as another 55,000 evacuated

    July 26, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Global marine protected areas fail to safeguard most sharks and rays: Study

    August 14, 2026

    $51 billion LNG megaproject takes ‘important’ step on path to FID by year-end

    August 14, 2026

    New records reveal efforts by North Carolina auditor’s office to sway county early voting decisions

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.