science1 distinct publisher
A backdoored litellm release turns every CI job that installed it into a credential incident
Datadog's investigation puts genuine PyPI releases of litellm and telnyx inside the same campaign that poisoned Trivy on March 19, which makes the unit of remediation the secrets the build could see rather than the version pin.
Publishers:securitylabs.datadoghq.com
Reality
- Evidence71
- Adoption62
- Hype gap−8
- Incentives58