{"id":4786,"date":"2026-08-12T16:18:21","date_gmt":"2026-08-12T16:18:21","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/12\/litellm-attack-affected-2500-companies-434000-ci-cd-pipelines-cloudsek\/"},"modified":"2026-08-12T16:18:21","modified_gmt":"2026-08-12T16:18:21","slug":"litellm-attack-affected-2500-companies-434000-ci-cd-pipelines-cloudsek","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/12\/litellm-attack-affected-2500-companies-434000-ci-cd-pipelines-cloudsek\/","title":{"rendered":"LiteLLM Attack Affected 2,500 Companies, 434,000 CI\/CD Pipelines: CloudSEK"},"content":{"rendered":"<div><img data-opt-id=747151859  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/akrites_open_source_supply_chain_security_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=774758616  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/akrites_open_source_supply_chain_security_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>The massive supply-chain attack that <a href=\"https:\/\/devops.com\/sophisticated-supply-chain-attack-targeting-trivy-expands-to-checkmarx-litellm\/\" target=\"_blank\" rel=\"noopener\">compromised LiteLLM<\/a> in the spring affected more than 2,500 companies and exposed about 434,000 CI\/CD pipelines, with victims ranging from top-tier IT and AI companies to cybersecurity firms, SaaS, and enterprises.<\/p>\n<p>It rolled up a lot of victims, but also was a high-profile example of the growing trend of threat actors targeting companies\u2019 AI infrastructure layer that is increasingly becoming connected to everything within their environments, according to CloudSEK threat researchers.<\/p>\n<p>The March attack on LiteLLM, a gateway and toolkit that lets developers call more than 100 large language model (LLM) providers \u2013 including Anthropic, Google\u2019s Gemini, and Amazon Web Services\u2019 (AWS\u2019) Bedrock \u2013 was the result of the threat group TeamPCP earlier that month compromising Aqua Security\u2019s <a href=\"https:\/\/www.aquasec.com\/blog\/trivy-supply-chain-attack-what-you-need-to-know\/\" target=\"_blank\" rel=\"noopener\">Trivy open source security vulnerability scanner<\/a> and its associated GitHub Actions.<\/p>\n<p>LiteLLM was compromised by TeamPCP but never directly attacked, according to CloudSEK\u2019s researchers. Instead, LiteLLM became part of a much broader campaign by the threat group after its CI pipeline installed the compromised Trivy scanner, leading to the publishing of releases 1.82.7 and 1.82.8 that included malicious code to the Python Package Index (PyPI) repository.<\/p>\n<p>\u201cTrivy, then the build system, then the LiteLLM release: one un-revoked token, three tools deep,\u201d the CloudSEK researchers <a href=\"https:\/\/www.cloudsek.com\/blog\/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines\" target=\"_blank\" rel=\"noopener\">wrote in a report<\/a>. \u201cThat chain is what turns a single credential leak into ecosystem-wide exposure.\u201d<\/p>\n<h3>Only 40 Minutes Were Needed<\/h3>\n<p>The two malicious LiteLLM packages remained on PyPI for about 40 minutes, but within that time, the damage was done. The researchers noted that automated build systems can compress time and that once an artifact containing malicious code gets into a registry, it can get copied quickly in scheduled jobs, dependency resolvers, developer laptops, and other tools.<\/p>\n<p>Given that, the threat remains even after the packages are removed, a key reason behind CloudSEK publishing the lists of compromised companies and affected pipelines.<\/p>\n<p>\u201cWe are sharing this openly so that every affected organization can act proactively,\u201d they wrote, adding that the \u201cthreat is still live. \u2026 Early awareness is the strongest defense; knowing you were impacted lets you rotate credentials, close the exposure, and harden before the next campaign hits.\u201d<\/p>\n<h3>Widespread Compromise<\/h3>\n<p>The warning echoes an <a href=\"https:\/\/www.ic3.gov\/CSA\/2026\/260702.pdf\" target=\"_blank\" rel=\"noopener\">advisory issued by the FBI<\/a> in July, which pointed to the TeamPCP\u2019s compromise of \u201csupply chain entry points\u201d that not only included Trivy and LiteLLM, but also KICS \u2013 an open source code analysis tool created by Checkmarx \u2013 and the Telnyx Python SDK.<\/p>\n<p>\u201cThese tools are commonly integrated into enterprise development continuous integration (CI)\/continuous delivery (CD) pipelines, cloud infrastructure, and security workflows,\u201d the FBI wrote. \u201cBy weaponizing these supply chain entry points, the threat actors were able to introduce malicious code into victim environments at scale.\u201d<\/p>\n<p>The agency also wrote that TeamPCP has collaborated with other threat groups and run extortion campaigns \u2013 publishing victim names on leak sites and threatening to disclose stolen data \u2013 and urged victim organizations to \u201ctreat exfiltrated data and credentials as a persistent risk, as affiliated threat actors are likely to weaponize them long after the initial compromise.\u201d<\/p>\n<h3>Stealing Credentials, API Keys, and Other Info<\/h3>\n<p>The malware distributed by TeamPCP included CanisterWorm, which harvests such sensitive information as cloud access tokens, credentials, API keys, and similar authentication material for cloud services like AWS, Google Cloud Platform, and Microsoft Azure, and SandClock, another info-stealer that targets AWS credentials, Kubernetes service account tokens, and cryptocurrency wallet data.<\/p>\n<p>There\u2019s also Mini Shai-Hulud, a self-replicating worm that targets npm and PyPI repositories for supply chain attacks, and Miasma, a Shai-Hulud variant that also self-propagates across npm and PyPI stealing credentials and damaging configuration files.<\/p>\n<p>\u201cThe loot was encrypted and shipped to a typosquatted domain,\u201d the researchers wrote. \u201cWhere exfiltration failed, the malware created a public repository inside the victim\u2019s own GitHub account and uploaded the stolen data there as a release asset, meaning some organizations were leaking their own secrets into public view without knowing it.\u201d<\/p>\n<h3>High-Profile Victims<\/h3>\n<p>The CloudSEK Threat Intelligence unit was able to access a dataset holding the information of victims, according to the researchers. The <a href=\"https:\/\/exposure.cloudsek.com\/ai-supply-chain-incident\" target=\"_blank\" rel=\"noopener\">list<\/a> includes a large number of well-known companies, including such tech, cloud, and SaaS companies as Nvidia, Intel, Zscaler, AWS, Cisco Systems, Salesforce, and ServiceNow.<\/p>\n<p>There also are numerous enterprises outside of IT, from John Deere and Airbus U.S. to FedEx, Volkswagen, Bayer, and Deloitte.<\/p>\n<p>The researchers cautioned that the company and pipeline numbers just refer to exposure to the threat, not necessarily that they\u2019ve been compromised.<\/p>\n<h3>Targeting AI Infrastructure<\/h3>\n<p>They also expect that AI infrastructure will increasingly become a target of cybercriminals, noting that such systems are becoming key junctions between data, identity, compute, and autonomous action. This trend would echo what\u2019s happened in the past.<\/p>\n<p>\u201cIn the industrial age, rail junctions became strategic targets because many supply routes met at one point,\u201d the researchers wrote. \u201cAI gateways, agent runtimes, MCP servers, and vector stores are becoming the junctions of digital operations. The [LiteLLM] incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it.\u201d<\/p>\n<p><a href=\"https:\/\/devops.com\/litellm-attack-affected-2500-companies-434000-ci-cd-pipelines-cloudsek\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>The massive supply-chain attack that compromised LiteLLM in the spring affected more than 2,500 companies and exposed about 434,000 CI\/CD [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4787,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4786","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4786"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4786\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4787"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}