ended4월 3일· 1 sources
PyPI 보안팀 공식 공급망 공격 사고 보고서: LiteLLM·Telnyx 악성 패키지 사건 그리고 방어하기
Why it matters
This official PyPI security report reveals a significant shift in supply chain attacks: rather than creating new malicious packages, attackers compromised established, widely-used packages like LiteLLM by stealing API tokens through dependency vulnerabilities. The incident affected over 119,000 downloads and demonstrates the critical need for developers to implement dependency cooldowns, proper lock files, and stronger authentication mechanisms like Trusted Publishers to prevent cascading compromise across the ecosystem.
1
Sources
+0
24h
—
Growth
163d
Active
supply chain attackPyPILiteLLMmalware injectionTrusted Publishers