Skip to content
live markets
S&P 5007,745.06▲ 3.85%NASDAQ26,644.91▲ 4.41%DOW53,459.78▲ 2.52%GOLD4,451.90▲ 10.95%WTI84.09▲ 1.94%BRENT90.93▲ 3.21%EUR/USD1.1579▲ 1.17%USD/JPY159.65▼ 1.68%DXY99.64▼ 1.11%BTC$64,212▲ 1.20%ETH$1,898▲ 0.00%SOL$76.06▲ 0.60%TOTAL CRYPTO$2.28T▲ 0.77%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

LiteLLM Supply Chain Attack Hits 2,500+ Firms, 434K Pipelines

CloudSEK reveals Nvidia, AWS, Cisco, Samsung, Deloitte and thousands more were exposed when TeamPCP poisoned the AI proxy library via a compromised Trivy dependency.

Partner Surfshark VPN

CloudSEK has disclosed that more than 2,500 organizations and approximately 434,000 CI/CD pipelines were potentially exposed by the LiteLLM supply chain attack in March 2026, making it the largest known AI-focused supply chain breach to date.

The cyber-intelligence firm published a full victim dataset on August 11 after months of analysis, naming Nvidia, AWS, Samsung, Salesforce, Cisco, Deloitte, the London Stock Exchange Group, FedEx, Volkswagen, Deutsche Bahn, and HP among the high-confidence matches. The list also includes Siemens, Orange, Zscaler, Epic Games, and dozens of other enterprise and government-linked organizations across multiple continents.

How a Single Token Compromised an Ecosystem

The attack originated when threat group TeamPCP compromised the Trivy open-source vulnerability scanner, which LiteLLM used as a CI dependency. When LiteLLM’s build pipeline automatically pulled the poisoned Trivy version, the attackers used a compromised maintainer credential to publish two malicious LiteLLM packages, versions 1.82.7 and 1.82.8, to the Python Package Index. Those packages were live for approximately 40 minutes, but the window was long enough for automated build systems to install them across thousands of environments.

“Trivy, then the build system, then the LiteLLM release: one un-revoked token, three tools deep,” CloudSEK researchers wrote. “That chain is what turns a single credential leak into ecosystem-wide exposure.” The modified packages contained malicious code that executed on every Python invocation with no explicit import required, sweeping SSH keys, cloud credentials from AWS, GCP, and Azure, Kubernetes tokens, environment variables, and LLM API keys from compromised runners.

FBI Warns Harvested Credentials Still Being Weaponized

A July 2026 FBI advisory, FLASH-20260702-01, warned that affiliated actors are likely to continue weaponizing the harvested credentials long after the original intrusion window closed. CloudSEK emphasized that removing a compromised package does not end the incident, as copied credentials can remain usable for weeks or months without rotation.

The stolen data was encrypted with AES-256 under a hardcoded RSA-4096 key and exfiltrated to a typosquatted domain. In cases where exfiltration failed, the malware created public repositories inside victims’ own GitHub accounts and uploaded stolen data as release assets, meaning some organizations were inadvertently leaking their own secrets into public view.

“The incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else.” – CloudSEK

AI Infrastructure Emerges as Prime Target

CloudSEK warned that the next major supply chain attack will likely target AI infrastructure directly, as these systems now serve as high-value junctions connecting data, identity, compute, and autonomous action. SOCRadar later reported that most of the 2,500 organizations were actually affected through the earlier Trivy compromise rather than LiteLLM specifically, though both vectors represent the same cascading supply chain failure.

The FBI advisory linked TeamPCP to a broader campaign that also compromised the KICS code analysis tool, the Telnyx Python SDK, and multiple npm packages. Sophos separately reported that TeamPCP has partnered with the Vect ransomware group to monetize the access obtained through these supply chain compromises, escalating the threat from data theft to active extortion.

Sources: CloudSEK; SecurityWeek; FBI FLASH-20260702-01; DevOps.com

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch SafePal Crypto Wallet Breach Exposes 40,000 Users Read →