A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.
The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.
It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.
Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.
Source: SecurityWeek