153GB of stolen credentials surface from LiteLLM attack

16 sources
  • Hudson Rock and CloudSEK published analyses of a 153GB archive linking 118,829 CI runner dumps to 2,488 corporate domains, including AWS, Samsung, Cisco , and Salesforce .
  • The breach originated when teen hacking group TeamPCP compromised the Trivy vulnerability scanner, then used stolen tokens to publish malicious LiteLLM versions to PyPI in a 40-minute window in March.
  • Researcher Kevin Beaumont said credentials at one major U.S. tech firm still worked months later despite claims they had been rotated, calling the breach a result of "poor AI security."
Sources (16)
  1. 1 153GB of stolen credentials surface after LiteLLM supply chain attack www.helpnetsecurity.com
  2. 2 LiteLLM breach data shows supply chain attack impacted 2,488 firms cyberinsider.com
  3. 3 Terabytes of credentials leaked in massive supply-chain ... arstechnica.com
  4. 4 LiteLLM PyPI Supply Chain Attack: What Happened & How to Fix It netenrich.com
  5. 5 Largest AI Supply Chain Breach of 2026: LiteLLM Hack ... www.infostealers.com
  6. 6 Malicious LiteLLM Releases Tied to Trivy Hack May Have ... thehackernews.com
  7. 7 litellm 1.82.8 Supply Chain Attack on PyPI (March 2026) | Tural ... www.linkedin.com
  8. 8 LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms www.cyberkendra.com
  9. 9 We May Be Living Through the Most Consequential Hundred ... ringmast4r.substack.com
  10. 10 The LiteLLM Supply Chain Attack: What Happened, Why It Matters ... www.herodevs.com
  11. 11 Mercor Data Breach: 4TB Stolen via Compromised AI Library www.linkedin.com
  12. 12 Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain ... www.trendmicro.com
  13. 13 International Cyber Digest x.com
  14. 14 FortiBleed: 75000 Fortinet Firewalls Compromised www.infostealers.com
  15. 15 Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack www.securityweek.com
  16. 16 Nightmare Eclipse Drops Windows Zero-Day Exploit ... www.securityweek.com