Vibe Coding
The LiteLLM build pulled an unversioned Trivy and shipped malware to 434,000 pipelines
paddo.dev's 2026-08-30 post traces the chain: credentials stolen from Aqua Security's Trivy on 27 February, 76 of 77 Trivy releases poisoned on 19 March, LiteLLM's build downloading the compromised unversioned dependency on 24 March and publishing two booby-trapped versions. CloudSEK's 11 August analysis put the blast radius at over 2,500 organisations and roughly 434,000 build pipelines, naming NVIDIA, Samsung, Cisco, Siemens, Vodafone and FedEx, with 3,459 secrets recovered from X Corp, 462 from Deloitte and 327 from Cisco. The compromised artifact was live for about forty minutes and it took five months to size the damage.
Source
↳ Follow the thread