1.
2.
How the Trivy supply chain attack harvested credentials from secrets managers
(news.ycombinator.com)
3.
Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
(bleepingcomputer.com)
4.
5.
Trivy supply-chain attack spreads to Docker, GitHub repos
(bleepingcomputer.com)
6.
Widely used Trivy scanner compromised in ongoing supply-chain attack
(arstechnica.com)