Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

https://www.securityweek.com/wp-content/uploads/2026/06/supply-chain-threat.webp

More than 2,500 organizations and over 430,000 CI/CD pipelines were affected by the LiteLLM supply chain attack earlier this year, CloudSEK reports.

The LiteLLM compromise was disclosed shortly after the supply chain attack on Aqua Security’s Trivy open source vulnerability scanner and was a direct result of it.

According to CloudSEK, TeamPCP, the threat actor behind multiple high-profile open source software (OSS) compromises, never targeted LiteLLM directly.

The open source Python library and proxy server was compromised after its CI pipeline installed the compromised Trivy version automatically. Two LiteLLM versions, namely 1.82.7 and 1.82.8, were pushed to PyPI, providing the hackers with access to all the information LiteLLM touched.

“Trivy, then the [LiteLLM] build system, then the LiteLLM release: one unrevoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure,” CloudSEK notes.

“Automated build systems compress time. Once a malicious artifact...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/LC3k7Ynwi6fhyasGQpKL4J-1920-80.jpg

'Bringing the game to console for the first time' means that ArenaNet 'can reach a much wider group of players' as devs say they want to offer an 'invitation' for everybody to play Guild Wars 3 together by bringing it to PS5 and PC — but not Xbox

* Guild Wars 3 is the first game in the series to launch on both PC and console * Studio head Colin Johanson says it will allow the game to "reach a much wider group of players" on PS5 and PC * ArenaNet wants new players to take their first plunge