How a Poisoned Scanner Reached 2,500 Companies Through One AI Supply-Chain Package

https://hackernoon.imgix.net/images/rymeSO93fMg9m2SRdMsCXRtvbhG2-k383bje.png

New data published around August 11, 2026, puts a hard number on a breach the software world has been underestimating since spring. The March compromise of LiteLLM — the open-source gateway thousands of teams use to route traffic to large language models — may have exposed secrets belonging to more than 2,500 organizations, according to a dataset analyzed by the threat-intelligence firm CloudSEK. The firm says the attackers walked away with roughly 434,000 files pulled from build pipelines around the world.

The reason the count keeps climbing is the shape of the attack. Nobody breached 2,500 companies one at a time. They poisoned one tool those companies trusted, and let the tool do the reaching.

Here is the chain, as reported by LiteLLM and multiple responders. On March 19, 2026, attackers compromised Trivy, a widely used open-source security scanner, and pushed malicious Trivy images to Docker Hub. That foothold —...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more