IncidentA Poisoned Security Scanner Backdoored a Python Package in Three Hours
On PyPI, malicious versions of LiteLLM were available for download for about three hours. The attack vector? A compromised Trivy GitHub Action that stole the maintainer s PyPI publishing credentials.














