Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #10
LiteLLM supply-chain attack hits tech, banking and healthcare
Original: LiteLLM Supply-Chain Attack — Technology, Banking and Healthcare the Most Affected 🚨 CRITICAL: TeamPCP's SANDCLOCK backd
Attackers used the SANDCLOCK backdoor, exploiting compromised LiteLLM maintainer credentials to push malicious PyPI packages, affecting more than 2,500 organisations across technology, finance and healthcare. The incident exposed cloud credentials and highlights the growing risk of open-source supply-chain compromises, with security researchers urging users to rotate secrets and update affected packages.
Why now: A critical supply-chain compromise of a widely used open-source tool puts thousands of organisations at risk, prompting urgent warnings and remediation efforts.
Evidence
- LiteLLM Supply-Chain Attack — Technology, Banking and Healthcare the Most Affected 🚨 CRITICAL: TeamPCP's SANDCLOCK backdoor exploited compromised LiteLLM maintainer credentials, hitting 2,500+ orgs across tech, finance & healthcare. Malicious PyPI packages exposed cloud… · hypedupcat@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/821339