Skip to content
Safety · Aug 13, 2026

Credentials for thousands of organizations exposed in LiteLLM supply-chain attack

Compromised versions of the AI development tool LiteLLM, distributed via the Python Package Index, led to the exfiltration of terabytes of sensitive data from over 2,500 users.

Trust79
HypeLow hype

1 source · cross-referenced

ShareXLinkedInEmail
TL;DR
  • Compromised versions of the AI development tool LiteLLM, distributed via the Python Package Index, led to the exfiltration of terabytes of sensitive data from over 2,500 users.
  • Security firms CloudSEK and Hudson Rock independently reported the breach, which occurred during a 40-minute window in March 2026.
  • Exposed data included cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider keys, affecting organizations such as Microsoft, Amazon, Cisco, Samsung, and Salesforce.
  • The attack was attributed to the TeamPCP hacking group and leveraged a prior compromise of the Trivy vulnerability scanner.

A supply-chain attack on LiteLLM, an open-source tool designed to streamline AI-driven software development, resulted in the exfiltration of terabytes of credentials and sensitive data from over 2,500 users. The compromised versions of LiteLLM—distributed via the Python Package Index—were active for a 40-minute window in March 2026, during which attackers scraped and exfiltrated data from infected machines.

Security firms CloudSEK and Hudson Rock independently reported the breach, with Hudson Rock analyzing a 195TB file containing the exposed data. The compromised versions of LiteLLM contained code that accessed the memory of infected machines, scraped its contents, and transmitted the data through attacker-controlled channels. The exposed data included cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys.

Among the organizations whose credentials were exposed are Microsoft, Amazon, Cisco, Samsung, Salesforce, Nvidia, AWS, Siemens, Airbus, and multiple other major corporations and institutions. Researchers noted that many of the exposed credentials lacked identifiable company-specific markers, making it difficult to attribute them to specific organizations. For example, an email address from the domain @siriusxm.com was traced to a subsidiary, AdsWizz, rather than the satellite broadcaster itself.

The attack was attributed to TeamPCP, a hacking group largely composed of teenagers, which also claimed responsibility for compromising the Trivy vulnerability scanner, KICS, and the Telnyx Python SDK in a broader campaign. The LiteLLM compromise originated from the earlier Trivy supply-chain attack, illustrating how cascading vulnerabilities in AI-adjacent tools can amplify the impact of such breaches.

The exposed data included 434,000 CI/CD pipeline credentials, with researchers warning that many organizations remain unaware of their exposure. Hudson Rock urged organizations using AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for LiteLLM versions 1.82.7 and 1.82.8, the compromised releases. The firm recommended aggressive credential revocation, including rotating cloud keys, Kubernetes service account tokens, and GitLab/GitHub personal access tokens (PATs).

The incident underscores broader concerns about the security of AI development tools and the rush to integrate AI into software delivery systems. Independent security researcher Kevin Beaumont noted that poor DevOps security practices, particularly in organizations prioritizing rapid AI adoption, exacerbated the scale of the breach. Beaumont also reported that at least one major US technology company had failed to fully rotate exposed credentials despite claiming to have done so, highlighting the challenges of effective incident response.

Sources
  1. 01Ars Technica — Technology LabTerabytes of credentials leaked in massive supply-chain attack
Also on Safety

Stories may contain errors. Dispatch is assembled with AI assistance and curated by human editors; despite the trust-score filter, mistakes happen. We correct publicly — every article links to its revision history. Nothing here is financial, legal, or medical advice. Verify before relying on any claim.

© 2026 Dispatch. No ads. No sponsorships. No paid placement. Reader-supported via Ko-fi.

Built by a person who cares about honest AI news.