Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trivy, Not LiteLLM, Caused 2,500 Organization Breach

Trivy, Not LiteLLM, Caused 2,500 Organization Breach

Posted on August 14, 2026 By CWS

Recent investigations by SOCRadar reveal that the compromise of over 2,500 organizations, initially attributed to a LiteLLM supply chain attack, actually stemmed from a previous breach involving the Trivy scanner. This clarification shifts the focus from LiteLLM to Trivy, a product of Aqua Security, highlighting the complexities of software supply chain vulnerabilities.

The Role of Trivy in the Attack

The breach, orchestrated by the threat group TeamPCP, involved malicious code that spread through the Trivy scanner, impacting numerous downstream packages and repositories. This ripple effect was intensified by the malware’s worm-like characteristics, which enabled automatic inclusion of harmful libraries across multiple builds. Reports from CloudSEK and HudsonRock earlier this week pointed to LiteLLM as the cause, but SOCRadar’s findings suggest otherwise.

TeamPCP’s attack pattern was consistent: once an infected package was accessed, malicious code executed automatically, harvesting sensitive data such as credentials, tokens, and API keys. The attackers used this stolen information to manipulate accessible packages and spread malicious versions, thus broadening the attack’s reach.

Timeline of the Compromise

SOCRadar’s detailed analysis of the LiteLLM incident data uncovered records for 2,188 affected entities, documenting timestamps, credential types, CI/CD platforms, and domains. The breach timeline spanned from March 19 at 18:05 UTC to March 24 at 20:09 UTC. Crucially, 95% of the compromised organizations ceased data collection before the malicious LiteLLM packages were registered, aligning more closely with the Trivy breach timeline.

The malicious Trivy build first surfaced on March 19, with a surge in activity occurring on March 22 and 23 when compromised Trivy images were accessible on Docker Hub. The incident concluded on March 24 following PyPI’s quarantine of the affected packages. This persistence indicates how the .pth payload continued to operate on already-infected systems even after the initial infection source was removed.

Impact on Organizations Worldwide

The breach affected six major CI/CD platforms, including GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite, with significant impacts noted in Germany, Brazil, and France. The malware targeted a wide array of secrets, with over 1,000 organizations inadvertently exposing JWT and authentication tokens. Additionally, hundreds of entities revealed private keys, AWS access keys, GitLab tokens, OpenAI API keys, Slack webhooks, and Google API keys.

SOCRadar reported that committer email addresses were compromised across more than 1,100 organizations, giving attackers access to both developer identities and machine tokens. Of the 2,188 organizations analyzed, 56% were rated high confidence in exposure, 39% medium, and 6% low, reflecting the challenge in attributing precise impacts to specific entities.

Currently, some of the stolen data is being traded on platforms like Telegram. This includes collections of data associated with LiteLLM, Trivy, and CanisterWorm, likely gathered at various stages of the attack campaign. The incident underscores the ongoing threat posed by supply chain attacks and the importance of robust cybersecurity measures to protect against such vulnerabilities.

Security Week News Tags:Bitbucket, Buildkite, CircleCI, Cybersecurity, Docker Hub, GitHub actions, GitLab CI, Jenkins, LiteLLM, Malware, security breach, SOCRadar, supply chain attack, TeamPCP, Trivy

Post navigation

Previous Post: HACKERAI Malware Utilizes GitHub for Command Control
Next Post: MessiahGPT AI Tool Fuels Cybercrime with Ransomware

Related Posts

Chrome 145 Fixes Critical Browser Vulnerabilities Chrome 145 Fixes Critical Browser Vulnerabilities Security Week News
NIST’s Single Photon Chip Boosts Quantum Security NIST’s Single Photon Chip Boosts Quantum Security Security Week News
River Bank Confirms Deletion of Ransomware-Stolen Data River Bank Confirms Deletion of Ransomware-Stolen Data Security Week News
Dashlane Faces Brute-Force Attack, Limited Data Affected Dashlane Faces Brute-Force Attack, Limited Data Affected Security Week News
US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator Security Week News
Data Breach at Madera Hospital Affects 150,000 People Data Breach at Madera Hospital Affects 150,000 People Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dysphoria Botnet Exploits IoT Devices for Cyber Attacks
  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack
  • MessiahGPT AI Tool Fuels Cybercrime with Ransomware
  • Trivy, Not LiteLLM, Caused 2,500 Organization Breach
  • HACKERAI Malware Utilizes GitHub for Command Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dysphoria Botnet Exploits IoT Devices for Cyber Attacks
  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack
  • MessiahGPT AI Tool Fuels Cybercrime with Ransomware
  • Trivy, Not LiteLLM, Caused 2,500 Organization Breach
  • HACKERAI Malware Utilizes GitHub for Command Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark