CloudSEK reported a major AI supply-chain breach involving LiteLLM that potentially exposed more than 2,500 organizations and roughly 434,000 CI/CD pipelines worldwide. The incident was described as one of the largest AI supply-chain compromises reported this year, with the affected dependency creating downstream exposure across enterprise development and deployment environments.
The reported blast radius includes potential access to cloud credentials, source-code repositories, Kubernetes environments, and broader AI infrastructure tied to impacted pipelines. The findings highlight how a compromise in a widely used AI component can propagate through software delivery chains and create enterprise-wide risk well beyond the original package or service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Resecurity reported that manifests from the LiteLLM/Trivy credential-harvesting archive identified 898 GitHub owners and 2,038 repositories, and named affected organizations including Microsoft, Azure, IBM, NVIDIA, FedEx, John Deere, TomTom, Deloitte, Bosch, ID.me, and 1inch. The report said the archive reflected capture activity between March 19 and March 24, 2026 and urged all referenced organizations to rotate exposed credentials immediately.
SOCRadar reported that most of the more than 2,500 organizations previously linked to the LiteLLM supply-chain attack were actually compromised earlier through Aqua Security's Trivy scanner. Its analysis of 2,188 organization records found that 95% of observed exposure activity ended before the malicious LiteLLM packages were published on March 24, shifting the primary impact assessment upstream to Trivy.
CloudSEK released a free tool to help organizations determine whether their credentials or infrastructure appear in the dataset tied to the LiteLLM supply-chain attack. It also advised potentially affected organizations to inspect relevant systems, review access logs, and rotate or revoke exposed credentials.
CloudSEK said the LiteLLM compromise was a downstream consequence of the earlier Trivy supply-chain attack and attributed the broader open source compromise activity to TeamPCP. It reported that LiteLLM's CI pipeline automatically installed a compromised Trivy version, leading to the malicious LiteLLM releases.
CloudSEK published research describing a LiteLLM AI supply-chain attack that it said potentially exposed more than 2,500 organizations and 434,000 CI/CD pipelines worldwide. The report said the incident created risks to cloud credentials, source-code repositories, Kubernetes environments, and AI infrastructure.
Hudson Rock said it discovered the LiteLLM exposure after analyzing a 195TB dataset containing stolen credentials, and Ars reported that CloudSEK and Hudson Rock publicly disclosed the exposure on Tuesday and Wednesday. Independent researcher Kevin Beaumont also said he verified the leaked data was legitimate and affected multiple organizations.
In July 2026, the FBI warned that actors linked to TeamPCP were likely to continue abusing credentials stolen during the LiteLLM-related supply-chain compromise long after the initial attack. The warning underscored that simply removing the malicious packages would not eliminate the risk if exposed secrets were not rotated.
Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, were published to PyPI on March 24, 2026 and remained available for about 40 minutes before being quarantined. The packages used a .pth file to automatically execute credential-stealing code and exfiltrate secrets from infected environments.
On March 19, 2026, attackers used compromised credentials to publish a malicious Trivy v0.69.4 release, part of the TeamPCP supply-chain campaign. The compromised Trivy component was later identified as the upstream stage that enabled theft of LiteLLM CI/CD secrets and the downstream malicious LiteLLM PyPI releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceresecurity.com
Open sourceheise.de
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcecloudsek.com
Open sourceexposure.cloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.