Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

helpnetsecurity+1arstechnica+1helpnetsecurity+1A 153GB archive containing credentials stolen during the March 2026 LiteLLM supply chain attack has surfaced, exposing sensitive data linked to nearly 2,500 organizations including Amazon Amazon.com, Inc. , Samsung, Cisco , Microsoft , NVIDIA , and Salesforce . Security firms Hudson Rock and CloudSEK published analyses of the data this week, revealing for the first time the full scope of an attack that lasted roughly 40 minutes in March but harvested secrets from more than 430,000 CI/CD pipelines.helpnetsecurity+2
The breach traces back to TeamPCP, a cybercriminal group that emerged in late 2025. On March 19, 2026, the group used stolen credentials to publish a compromised version of Trivy, a widely used open-source vulnerability scanner. LiteLLM's build pipeline installed Trivy automatically, giving the poisoned scanner access to the runner environment and allowing attackers to steal the project's PyPI publishing tokens.arstechnica+1
Using those tokens, TeamPCP published two malicious LiteLLM releases — versions 1.82.7 and 1.82.8 — to the Python Package Index on March 24. The malware harvested environment variables, AWS credentials, Kubernetes configurations, SSH keys, and AI provider API keys, then exfiltrated them through attacker-controlled infrastructure.helpnetsecurity+3
Hudson Rock's analysis attributed 118,829 CI runner dumps to 2,488 corporate domains. CloudSEK, working from a separate dataset, corroborated the figures, identifying more than 2,500 potentially affected organizations. Both firms stressed their findings reflect exposure rather than confirmed breaches.infostealers+3
Among the organizations linked to exposed credentials are Volkswagen, FedEx , Deloitte, ServiceNow , S&P Global , Siemens, and BT Group.helpnetsecurity+1
"I've confirmed the data is legit by the way, multiple victim orgs," independent security researcher Kevin Beaumont wrote, adding that the breach stemmed from "poor AI security — not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security."arstechnica+1
Despite months having passed since the initial compromise, some organizations have yet to rotate exposed credentials. Beaumont reported that one major U.S. technology company claimed it had rotated all affected keys, but when he tested them — permitted under the company's own responsible disclosure policy — "almost every one worked."helpnetsecurity
Hudson Rock co-founder Alon Gal said the data is not yet circulating publicly, creating "a critical window of opportunity for companies to rotate keys and secrets before it eventually leaks." Organizations are urged to treat any secrets accessible to LiteLLM versions 1.82.7 or 1.82.8 as compromised, rebuild affected CI runners, and review logs dating back to March 24.thehackernews+2