PyPI에서 발견된 악성 LiteLLM 릴리스로 2100개 이상의 조직이 노출됐다는 보고.
악성 LiteLLM 릴리스가 PyPI에서 약 40분 동안 존재하며 클라우드 키, SSH 키, Kubernetes 토큰, 데이터베이스 비밀번호 등을 탈취할 수 있는 코드가 포함되어 있었습니다. 위협 정보 회사인 CloudSEK는 공격자들이 포착한 약 434,000개의 파일로 구성된 데이터셋을 분석하여 노출된 조직 수를 파악했습니다. 이 사건은 보안 위협을 크게 증가시킬 수 있는 사례입니다.
Malicious LiteLLM releases on PyPI may have exposed over 2,100 organizations.
Malicious LiteLLM releases were on PyPI for around 40 minutes, containing code capable of stealing cloud keys, SSH keys, Kubernetes tokens, and database passwords. Threat intelligence firm CloudSEK reports that a dataset it obtained, derived from approximately 434,000 files captured by the attackers, maps potential exposure to numerous organizations. This incident significantly raises security threat levels.