LiteLLM supply chain breach quietly exposed over 2,500 companies for months before anyone noticed

Started by Seb93, Today at 07:07 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: LiteLLM supply chain breach quietly exposed over 2,500 companies for months before anyone noticed   Views(Read 19 times)
Active members in this topic:
Seb93(1)

Seb93

CloudSEK has published research showing a March 2026 compromise of the LiteLLM project, a widely used AI gateway library, potentially exposed more than 2,500 organizations and around 434,000 CI/CD pipelines worldwide

The attack chain is the part that really got me, a group called Team PCP first compromised the Trivy security scanner that LiteLLM's own build pipeline relied on, then used that foothold to poison LiteLLM packages on PyPI, the malicious versions were live for only about 40 minutes

Forty minutes sounds trivial until you remember how CI/CD systems work, automated pipelines can pull and execute a dependency within seconds of publication, so a short window is more than enough when the download happens automatically rather than by a human clicking install

The list of high confidence matches CloudSEK flagged includes some very large names, Nvidia, AWS, Cisco, Salesforce, Siemens, Samsung, Deloitte and X among others, though CloudSEK is careful to note a high confidence match is not proof of actual successful compromise, it just means strong evidence the credentials or pipeline touched the exposure

The FBI's FLASH advisory from July is the part that should worry people most, it explicitly warns that stolen credentials from this window can still be weaponized months later, which means plenty of affected organizations may not even know they need to rotate secrets because there is no clean attribution trail pointing back to them

This is basically the nightmare scenario for the AI supply chain, a gateway library sitting right at the choke point between applications and provider API keys got compromised through a dependency of a dependency, and the blast radius is still not fully mapped five months later

Posted from my main account

Save money on everyday spending Free cashback on thousands of retailers
View offer