Skip to main content
Live
Main content

LiteLLM supply-chain attack leaks credentials from 2,500 organizations

A 40-minute window in March exposed secrets across 434,000 CI/CD pipelines at Microsoft, Amazon, Cisco, Samsung, Salesforce, and Nvidia.

Jaeden Schafer
Editor in Chief · · 5 min read
LiteLLM supply-chain attack leaks credentials from 2,500 organizations

A 40-minute supply-chain attack on LiteLLM, an open-source tool used to wire large language models into software pipelines, leaked terabytes of credentials from 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, Salesforce, and Nvidia. Security firms CloudSEK and Hudson Rock disclosed the breach this week after Hudson Rock analyzed a 195TB file containing the stolen data. In total, 434,000 CI/CD pipelines had secrets exposed while running compromised versions 1.82.7 and 1.82.8 of the package, downloaded from the Python Package Index.

The scraped data includes cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys. Confirmed victims extend well beyond the big AI names: ServiceNow, Siemens AG, S&P Global, Airbus US Space & Defense, John Deere, Regeneron Pharmaceuticals, London Stock Exchange Group, Thomson Reuters, FedEx, Volkswagen, Deloitte, Kroger, HP, Philips, Vodafone, BT Group, Epic Games, and X Corp all appear on the high-confidence victim list published by the researchers.

The compromise did not originate in LiteLLM itself. It was a downstream consequence of an earlier supply-chain attack on Trivy, the widely used vulnerability scanner, along with KICS and the Telnyx Python SDK. All four packages ended up carrying code that read the memory of infected machines, scraped its contents, and exfiltrated the results to an attacker-controlled channel. Credit for the campaign has been claimed by TeamPCP, a group researchers describe as largely made up of teenagers and which independent analysis has largely corroborated.

Key facts

  • 01A compromised version of LiteLLM exfiltrated credentials from 2,500 organizations during a 40-minute window in March.
  • 02Some 434,000 CI/CD pipelines had secrets exposed, harvested from versions 1.82.7 and 1.82.8 of the package.
  • 03Confirmed victims include Microsoft, Amazon Web Services, Nvidia, Cisco, Samsung, Salesforce, ServiceNow, and the London Stock Exchange Group.
  • 04Hudson Rock analyzed a 195TB file containing the stolen data; the group TeamPCP has claimed responsibility.
  • 05The LiteLLM breach originated in an earlier supply-chain compromise of the vulnerability scanner Trivy, whose developers left an automation token live for 20 days after rotation.

Independent security researcher Kevin Beaumont has been tracking the fallout and confirmed the data's authenticity with multiple affected organizations.

CloudSEK and Hudson Rock both stressed that many of the exposed secrets cannot be tied back to a specific victim by hostname or email domain. Generic CI/CD pipeline variables often contain active database passwords, third-party API keys, and cloud credentials with no identifying string attached. Hudson Rock warned that "countless organizations currently have active secrets sitting in this database, completely unaware of their exposure." That opacity is why the researchers are urging blanket rotation across any environment that ran the affected LiteLLM builds.

The Trivy origin story is itself a lesson in incomplete remediation. According to CloudSEK, Trivy developers rotated an automation token after the initial compromise but failed to fully revoke it for 20 days, giving attackers a nearly three-week window to force-push malicious code into third-party builds that pulled the scanner. That single lapse cascaded into LiteLLM, and from LiteLLM into hundreds of thousands of build pipelines running at organizations that had no direct relationship with either package's maintainers.

Hudson Rock co-founder Alon Gal framed the magnitude bluntly in a written statement.

A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.
Alon Gal, Hudson Rock co-founder and CTO

Early signs suggest some affected organizations are underestimating the scope. Beaumont reported that after one large US tech company told him it had rotated all exposed credentials and dismissed the incident, he tested the leaked secrets under the company's own responsible-disclosure policy and found that "almost every one worked." The credentials date to March, meaning any secret not aggressively revoked in the intervening months is still live in the dump. Hudson Rock is telling anyone who touched the compromised LiteLLM versions to assume every secret accessible to that environment is compromised and to rotate cloud keys, Kubernetes service tokens, and Git platform PATs.

Related · from this week
BadHost vulnerability exposes millions of AI agents to credential theft
Jaeden Schafer · 5 min read →

The specific rot here is not that AI tooling is inherently unsafe — LiteLLM is a proxy layer, not a model — but that the rush to plug LLMs into production build systems has multiplied the blast radius of any single compromised dependency. A 40-minute window inside one open-source package now cascades into hundreds of thousands of pipelines at Fortune 500 companies, banks, defense contractors, and pharmaceutical firms. Vendors selling AI developer platforms will face harder procurement questions in the next quarter, particularly on dependency provenance and token revocation SLAs. The organizations that treat this as a nothingburger, as Beaumont's spot-check suggests some already are, will be the ones supplying the next set of headlines.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

BadHost vulnerability exposes millions of AI agents to credential theft
Security

BadHost vulnerability exposes millions of AI agents to credential theft

CVE-2026-48710 affects Starlette, a Python package with 325 million weekly downloads, allowing trivial authentication bypass.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic details eight months of Claude abuse, from state hacking to bioweapon attempts

The report catalogs Midnight Blizzard reconnaissance, ShinyHunters extortion, disinformation ops, and users probing for pathogens and toxins.

Jaeden Schafer5 min read
OpenAI logo
Security

New Mexico Supreme Court fines lawyer $5,000 for ChatGPT-fabricated witnesses

Stephen Aarons fed a murder trial transcript into ChatGPT's o3 model and filed a brief citing testimony from witnesses who never existed.

Jaeden Schafer5 min read