Vect Ransomware Wipes Data from LiteLLM Supply Chain Victims

Organisations affected by the LiteLLM and Trivy supply chain compromises paid Vect to recover their data. The recovery tool was a wiper; it destroyed any file larger than 128KB and left nothing recoverable, even for the attacker. The service was called ransomware, but its actual product was closure.

Severity: Unrated · Category: Supply Chain

Impact: Data destruction via wiper disguised as ransomware

Source: The Register · Apr 28 2026

How Fencio prevents this

The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.

Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.

All incidents