A poisoned LiteLLM release hit 2,500+ companies
Archive item — written before sources were shown.
A March supply-chain attack on the open-source LiteLLM AI gateway stole credentials from 434,000 CI/CD pipelines. The FBI warns the stolen data is still live.
Security researchers this week detailed the scale of a supply-chain attack that hit LiteLLM, a widely used open-source gateway for routing requests across AI providers, back in March. The threat group TeamPCP didn’t attack LiteLLM’s own code directly: it had already compromised the GitHub Action for Trivy, a security scanner LiteLLM’s CI/CD pipeline installed without pinning to a verified version. The poisoned scanner stole LiteLLM’s PyPI publishing token, letting TeamPCP upload two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, straight to the official package index.
Anyone who installed those versions got a hidden payload that activated the moment Python started, whether or not LiteLLM was actually imported, and immediately began harvesting environment variables, cloud config files, and Kubernetes credentials, while attempting lateral movement and installing a persistent backdoor. CloudSEK now counts more than 2,500 potentially exposed organizations and roughly 434,000 CI/CD pipelines; Hudson Rock independently obtained the attackers’ exfiltration archive and tied 118,829 stolen CI runner dumps to 2,488 corporate domains, including Amazon Web Services, Samsung, Cisco, Salesforce, Siemens, and Deloitte. The FBI’s July advisory warns the stolen credentials are still being actively exploited.
What it means for you
The attack chain here is the real lesson: LiteLLM’s own source code was never touched, the compromise came through an unpinned dependency of a dependency, a security scanner installed to make the pipeline safer that instead became the entry point. If your CI/CD pipeline installs any tool, scanner, linter, or action without pinning it to a specific verified version and checksum, you have the same exposure this attack exploited, regardless of whether you use LiteLLM specifically. Audit your pipeline for anything pulled at “latest” rather than a pinned, verified version, and treat every credential that has ever touched a CI runner as potentially compromised if you were running an affected LiteLLM version between March and now, rotating is cheaper than assuming you’re fine. This sits alongside Anthropic’s own reasoning-trace credential leak as a reminder that the AI tooling supply chain, gateways, SDKs, scanners, and the infrastructure wired around your model calls, is now a live attack surface in its own right, not just the models themselves.
- 012,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026cloudsek.com · primary, research report
- 02Gargantuan trove of stolen secrets surfaces from LiteLLM supply chain attackcybernews.com · reporting
