avatar
The Hacker News
@thehackernews
24.03.2026 23:31
�� Malicious LiteLLM versions 1.82.7–1.82.8 deploy credential theft, Kubernetes lateral movement, and a persistent backdoor.

Linked to the Trivy CI/CD compromise, the payload runs on import or via .pth at Python startup, spreads across nodes, and installs a systemd service.

�� Full story → https://thehackernews.com/2026/03/teampcp-backdoors-litellm-versions.html
🤯 12
🔥 10
3
😁 3
👍 1
36 9.1K

Обсуждение 0

Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.

Обсудить в Telegram

The Hacker News

162.3K
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Открыть в Telegram