Security Scanner Bug, Not LiteLLM, Behind Breach Affecting 2,500 Organisations
A recent security incident that impacted more than 2,500 organisations was initially linked to malicious versions of the LiteLLM software package. However, further investigation has revealed that the true cause was an issue with Trivy, a widely used open-source security scanning tool.
Critically, researchers found that over 95% of the affected companies were already exposed before the malicious LiteLLM packages were even published. This means the vulnerability existed independently of the LiteLLM supply chain issue that was originally blamed, pointing instead to a weakness in how Trivy itself handled scanning or reporting.
This case highlights a growing challenge for businesses: the tools used to detect security risks can themselves become a source of risk if not properly maintained and verified. For small businesses relying on open-source security tools, it's a reminder that even trusted software requires ongoing scrutiny and prompt patching when issues are identified.