Trivy, not LiteLLM behind the 2,500 organization compromise

Trivy, not LiteLLM behind the 2,500 organization compromise

According to SOCRadar, most of the 2,500 organizations believed to have been affected by the LiteLLM supply chain attack had previously been exposed.

The compromise was attributed to TeamPCP and claims to be the threat actor behind multiple open source software (OSS) supply chain attacks involving the Shai Hulud worm.

It started with Aqua Security’s Trivy scanner and spread downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by automatically including the malicious libraries in further builds.

More than 2,500 organizations were likely affected by the LiteLLM, CloudSEK and Hudson Rock said earlier this week. Accordingly SOCRadarmost of them were victims of the Trivy compromise, not LiteLLM.

All TeamPCP-related compromises followed a similar pattern: malicious code was automatically executed as the infected package was retrieved and executed to collect credentials, tokens, API keys, and other secrets.

Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions into the registry, thereby increasing the attack surface.

Advertising. Scroll to continue reading.

This is how LiteLLM was compromised and two poisoned package versions were released on March 24th, which remained online for about 40 minutes.

They were injected with a .pth file that automatically ran Python when the interpreter started, even if LiteLLM was never imported, thus bypassing the ignore script protection.

The compromise period

According to SOCRadar, a close examination of LiteLLM incident data revealed records per organization for 2,188 entities, including timestamps, credential types, CI/CD platforms, and domains.

“Each record has a “First Seen” and “Last Seen” timestamp. The earliest is March 19 at 18:05 UTC and the latest is March 24 at 20:09 UTC, a span of just over five days,” the cybersecurity company notes.

Data collection ended before March 24 for 2,085 organizations, or 95% of the 2,188 identified organizations The poisoned LiteLLM packages were published in the registry.

“This timing is consistent with the upstream Trivy compromise and not the LiteLLM install window. The 40 minutes everyone reported was the final act, not the entire game,” SOCRadar says.

The earliest capture was 18 minutes after the malicious Trivy build was released on March 19th. Activity increased on March 22 and 23 when malicious Trivy images were live on Docker Hub, and was shut down on March 24 after PyPI quarantined the packages.

“(This) is what persistence looks like on already infected hosts: The .pth payload continued to run after the infection source disappeared,” SOCRadar notes.

The compromise affected six CI/CD platforms, namely GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI and Buildkite, and affected organizations worldwide, with Germany, Brazil and France most affected.

Stolen secrets now imparted

The malware broadly targeted secrets, but over 1,000 organizations exposed JWT and authentication tokens. Hundreds of them exposed private keys, AWS access keys, GitLab tokens, OpenAI API keys, Slack webhooks, GitHub action tokens and Google API keys.

“The highest number of secrets in the group is approximately 3,477 (the organization was not named), followed by approximately 3,459. Several highly classified lines are based on very few files or repositories. One line contains 3,459 secrets in just six files,” SOCRadar notes.

The cybersecurity company also notes that email addresses of perpetrators in over 1,100 organizations were compromised. In these cases, the attackers have both developer identities and machine tokens.

“Of the 2,188 organizations in the record-level data set, 56% are rated high trust, 39% are rated medium, and 6% are rated low trust, with numbers rounded. More than 2,500 organizations are named in the headline coverage; the difference reflects which records carry assignable identifiers,” SOCRadar notes.

“High confidence matches are based on the identity of the CI host and the legitimate committer domains, i.e.

The stolen information is already being conveyed. A threat actor offers a collection of LiteLLM, Trivy, and CanisterWorm data on Telegram, likely compiled at different stages of the campaign.

Related: Over 400 NPM packages infected in ChainDrop supply chain attack

Related: North Korean hackers target open source developers in supply chain attacks

Related: North Korean hackers blamed for Mastra NPM supply chain attack

Related: Hackers exploit unpatched GeoServer zero-day

Leave a Reply

Your email address will not be published. Required fields are marked *