The LiteLLM Chain Reaction — From Trivy to PyPI, a Textbook AI Supply-Chain Meltdown

TeamPCP compromised Aqua Security's Trivy CI/CD to plant a three-stage payload in LiteLLM 1.82.7–1.82.8. The supply-chain attack exposed API keys and cloud credentials by targeting the tooling layer that connects AI models to applications.