How a Poisoned Scanner Reached 2,500 Companies Through One AI Supply-Chain Package
us.headtopics.com Sep 22, 2026

How a Poisoned Scanner Reached 2,500 Companies Through One AI Supply-Chain Package

AI-summarised brief · reviewed before publication

CloudSEK’s August 11, 2026 data shows that a March 2026 compromise of the open‑source AI gateway LiteLLM and the security scanner Trivy exposed secrets from more than 2,500 organizations. Attackers first poisoned Trivy images on Docker Hub, then released malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. Automated CI/CD pipelines installed these packages, allowing the malware to harvest 434,000 files containing cloud keys, SSH tokens, and database passwords. The breach enabled attackers to access downstream projects, including Checkmarx GitHub repos, Cisco source code, and a European Commission AWS account.

💡 Why It Matters

  • · The incident demonstrates how a single compromised dependency can cascade across thousands of organizations, turning routine build processes into a global credential‑exfiltration vector.
  • · It underscores the urgency of supply‑chain vigilance in modern DevOps workflows.