Vect Ransomware Wipes Data from LiteLLM Supply Chain Victims
Organisations affected by the LiteLLM and Trivy supply chain compromises paid Vect to recover their data. The recovery tool was a wiper; it destroyed any file larger than 128KB and left nothing recoverable, even for the attacker. The service was called ransomware, but its actual product was closure.
Severity: Unrated · Category: Supply Chain
Impact: Data destruction via wiper disguised as ransomware
Source: The Register · Apr 28 2026
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.