Hackers Supply Chain Attack Moves From npm to PyPI as Trivy Breach Extends into LiteLLM Package
Blog post from Semgrep
A recent series of supply chain attacks has highlighted vulnerabilities across multiple ecosystems and distribution channels, beginning with a compromised token and CI misconfiguration in the Trivy security scanner. The attack evolved into a multi-stage chain, affecting GitHub Actions, Docker images, npm packages, and Python libraries, with the attackers leveraging stolen credentials to move laterally and expand their reach. Particularly affected were the LiteLLM Python library, which serves as a unified interface for different LLM APIs, and Trivy, which was exploited to push malicious releases that exfiltrated sensitive credentials. The attackers also aimed to embarrass security vendors like Checkmarx by compromising their GitHub Actions. The malware involved in these attacks is sophisticated, employing hybrid encryption to secure stolen data, and uses components like orchestrators, harvesters, and backdoors to persist and escalate privileges in affected systems, including Kubernetes environments. As the situation unfolds, affected parties are advised to rotate credentials and monitor for further compromises, with the potential for additional attacks from the same threat actors remaining high.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 12 | 1,840 | 308 | 106 | +33% |
| Secrets Management | 9 | 1,488 | 268 | 99 | +7% |
| LLM | 3 | 6,078 | 960 | 218 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.