Mastodon Skip to content
live markets
S&P 5007,707.98▲ 3.36%NASDAQ26,331.09▲ 3.18%DOW53,463.05▲ 2.52%GOLD4,543.20▲ 13.29%WTI86.56▲ 4.00%BRENT93.76▲ 5.09%EUR/USD1.1712▲ 2.49%USD/JPY158.26▼ 2.61%DXY98.59▼ 2.38%BTC$71,920▲ 11.40%ETH$2,284▲ 18.50%SOL$87.46▲ 12.70%TOTAL CRYPTO$2.45T▲ 8.43%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- bluesky ↗ Join the wire

LiteLLM Supply-Chain Attack Hits 2,500+ Orgs

TeamPCP compromised the popular AI gateway library, exposing GitHub tokens, cloud keys and API secrets across Microsoft, NVIDIA, IBM and hundreds more

Partner Surfshark VPN

A supply-chain attack on LiteLLM, a widely used open-source AI gateway, has exposed credentials belonging to more than 2,500 organizations including Microsoft, NVIDIA, IBM, PayPal, and Deloitte, according to a new report from Resecurity.

The attack, tracked under the moniker “SANDCLOCK,” was carried out by the threat actor group TeamPCP, which compromised maintainer credentials for LiteLLM and published two malicious package versions, 1.82.7 and 1.82.8, to PyPI around March 2026. The compromised versions installed a credential stealer that harvested GitHub tokens, AWS and GCP keys, Kubernetes secrets, SSH credentials, and API keys for AI providers including OpenAI and Anthropic.

Scope of the Damage

Resecurity acquired a 150GB archive of data attributed to the attack and found 898 compromised GitHub owners across 2,038 repositories. The affected organizations span technology, banking, healthcare, retail, manufacturing, and government sectors. Among the named victims are Microsoft, Azure, NVIDIA, IBM, PayPal (Zettle), Deloitte, Bosch, S&P Global, Elevance Health, Kroger subsidiary 84.51, Leroy Merlin parent Adeo, Dräger, ID.me, and the decentralized exchange 1inch.

The attack leveraged the fact that LiteLLM is present in approximately 36% of cloud environments and is downloaded millions of times daily. Malicious version 1.82.8 was particularly aggressive, executing on any Python startup rather than requiring an explicit import. The payload installed a .pth file into Python’s site-packages directory that executed automatically, harvesting and exfiltrating credentials to an attacker-controlled domain.

AI Ecosystem at Risk

LiteLLM serves as a unified API layer for more than 100 large language model providers, making it a critical piece of infrastructure for AI development teams. The library’s broad adoption meant that compromised versions were pulled tens of thousands of times, creating an extremely large blast radius across the AI ecosystem.

“The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software working together,” researchers noted, describing how the stolen credentials could be used to pivot into cloud infrastructure, CI/CD pipelines, and production systems.

The attack chain began with the compromise of a GitHub Action in the Trivy security scanner, which was then expanded to checkmarx and ultimately LiteLLM. Resecurity’s analysis of victim manifests showed that 631 of the 898 affected GitHub owners had a single compromised repository, while the most-affected organization had 64 repositories exposed.

Resecurity has urged all affected organizations to immediately revoke or rotate GitHub App private keys, personal access tokens, AWS and GCP credentials, container registry tokens, SSH keys, and signing passwords. The attack highlights the growing risk of supply-chain compromises targeting AI and open-source infrastructure, where a single compromised library can cascade across thousands of downstream users.

Sources: Resecurity; SecurityAffairs; Bleeping Computer; Check Point Research

React to this dispatch
Share this dispatch X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch CISA Flags Exploited Microsoft, VMware, Apple Flaws Read →