The Supply-Chain Attack Was Bigger Than the Package Everyone Blamed

The LiteLLM supply chain attack began upstream in Trivy. Trusted security tooling, stolen secrets and automated CI/CD turned one breach into a wider exposure graph.

The LiteLLM supply chain attack began upstream in Trivy. Trusted security tooling, stolen secrets and automated CI/CD turned one breach into a wider exposure graph.

The European Commission used a compromised version of a trusted security scanner. The resulting breach shows that build tools can become credential-harvesting infrastructure inside the systems they are meant to protect. CERT-EU published its investigation into a European Commission cloud…