Cybersecurity

LiteLLM supply-chain attack leaks credentials of 2,500+ orgs

Published Aug 12, 2026, 10:16 PM2 min readNewUJ Editorial Desk

LiteLLM supply-chain attack leaks credentials of 2,500+ orgs
Photo: Markus Spiske · Unsplash
0 0
XWhatsAppTelegramLinkedIn

A supply-chain attack on LiteLLM, an open-source tool that streamlines AI-driven software development, exposed terabytes of credentials belonging to more than 2,500 organizations, including Microsoft, Amazon, Cisco, Samsung and Salesforce. Security firms CloudSEK and Hudson Rock disclosed the breach on August 11 and August 12, 2026.

The stolen credentials were harvested during a 40-minute window in March 2026 from machines running LiteLLM versions 1.82.7 and 1.82.8, which had been downloaded from the official Python Package Index repository. Hudson Rock analyzed a 195TB file and confirmed that roughly 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed.

Researchers often could not attribute many credentials to specific organizations because pipelines lack identifiable company information, though CloudSEK and Hudson Rock published a high-confidence list of affected entities. The LiteLLM compromise stemmed from an earlier supply-chain attack on the vulnerability scanner Trivy, which also infected KICS and the Telnyx Python SDK.

TeamPCP, a group largely composed of teenagers, claimed responsibility, and researchers have largely corroborated that claim. Independent security researcher Kevin Beaumont said he confirmed the data's legitimacy with multiple victim organizations and that the breach resulted from poor AI security and rushed DevOps practices rather than from AI itself being the threat.

The stolen data includes active database passwords, third-party API keys and cloud credentials, many of which remain valid. CloudSEK and Hudson Rock are urging all organizations that used the compromised LiteLLM versions to rotate all pipeline credentials immediately. Hudson Rock advised affected parties to assume any secret accessible to the LiteLLM environment is compromised, invalidate cloud keys and Kubernetes tokens, and audit logging and egress filtering.

Trivy developers rotated but failed to fully revoke an automation token over a 20-day period, giving attackers nearly three weeks to push malicious code to third-party builds, CloudSEK said. "This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry," said Alon Gal, co-founder and chief technology officer of Hudson Rock.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.