<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Trivy Compromise, Not LiteLLM, Drove Most of the March Supply Chain Exposure

SOCRadar found 95% of identified organizations had data taken before the LiteLLM releases appeared. The March 19 Trivy compromise was the main vector.
Content Team

A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.

The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.

It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.

Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo