· PyPI
LiteLLM releases compromised through the build supply chain ↗
JFrog documented backdoored PyPI releases after a compromised Trivy build tool exposed publishing credentials. The report describes credential theft and the project’s change to a pinned Trivy version.
Affected versions: 1.82.7 and 1.82.8
Packages: litellm
Source: JFrog Security Research