In March 2026, a threat actor group called TeamPCP compromised the CI/CD pipeline of Trivy, one of the most widely used open source vulnerability scanners in the industry. This access was used to steal the publishing credentials of LiteLLM, another very popular open source AI proxy gateway. Five months later the consequences of that single […] The post The LiteLLM Supply Chain Attack: How a Poisoned Scanner Exposed 2,000+ Organizations’ AI and Cloud Credentials appeared first on CybelAngel .