Trivy Was the Primary Vector: Most of 2,488 LiteLLM Breach Victims Never Installed 1.82.7 or 1.82.8 — One Unrevoked Token, 20 Days, 76 trivy-action Tags Poisoned — Re-Audit From March 19
SOCRadar confirmed: most organizations in the 153GB breach archive were exposed via the Trivy compromise beginning March 19 — not the 40-minute LiteLLM PyPI window on March 24. TeamPCP never targeted LiteLLM directly. One unrevoked automation token gave them write access to Trivy for ~20 days, poisoning 76 of 77 trivy-action version tags. Any CI/CD pipeline using tag-based Trivy references during that window had credentials harvested — regardless of LiteLLM usage. CVE-2026-33634 in CISA KEV. Pin Actions to commit SHAs. Verify token revocation completely.
Read Full Brief →Threats & Attacks
One unrevoked token → 20 days → 76 of 77 trivy-action tags poisoned. CI/CD pipelines using Trivy via tag references were compromised directly. LiteLLM packages were Stage 3, not Stage 1. CVE-2026-33634 KEV.
8 agents, 12 waves, Hermes + OpenClaw (free). 21 systems, 85 accounts, 2,500+ records, nuclear safety, 7 energy firms. “The cost of running a competent attack has collapsed.”
TeamPCP → Trivy → LiteLLM CI → malicious packages → 40 min PyPI. The 40-minute window was Stage 3. Most victims were hit at Stage 1. FBI active. Article #61 has the full correction.
Four JWT weaknesses. No auth. Admin impersonation. Chain to RCE. Trivy breach exposed the domain credentials that power this attack. Patch both CVEs now.
All prior models High. Astra Critical. Taiwan shows what that capability looks like deployed. Both confirmed in the same week.
Upload file → hidden instructions → Rovo URL retrieval → all data sent to attacker. No approval. Disabling web search doesn’t stop it. One route still unconfirmed closed.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
