
LiteLLM Supply Chain Poisoning: A Full-Path Analysis from Trivy Compromise to Zero-Click Malicious .pth Injection
The popular AI framework LiteLLM has fallen victim to a severe supply chain poisoning attack. The threat actor, TeamPCP, compromised the upstream tool Trivy to steal publishing tokens, subsequently planting a malicious version in the PyPI repository equipped with fork bomb capabilities and container escape functionality.
VULNERABILITY ALERTS

