security1 distinct publisher
Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD
Two litellm releases that never came out of the project's CI harvested SSH keys and cloud credentials from every host that installed them. litellm traces the entry point to the Trivy scanner in its own pipeline.
Publishers:github.com
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+12
- Incentives78