Thursday, August 27, 2026
Tech Beat
Aug 12, 2026, 9:43 PMCybersecurity

LiteLLM Supply Chain Attack Exposes Secrets From 434,000 CI/CD Pipelines

LiteLLM versions 1.82.7 and 1.82.8 exposed credentials from 434,000 CI/CD pipelines, putting more than 2,500 organizations at risk worldwide in March.

A poisoned gear fractures a vast clockwork, symbolizing one compromised dependency spreading secrets across organizations.
Listen to this briefingAudio briefing

Summary

CloudSEK and Hudson Rock said LiteLLM versions 1.82.7 and 1.82.8, distributed through the official Python Package Index for 40 minutes in March, scraped machine memory and exfiltrated terabytes of data. Roughly 434,000 CI/CD pipelines across tens of thousands of users exposed millions of secrets, potentially opening more than 2,500 organizations to intrusion. Hudson Rock discovered the breach while analyzing a 195TB file from an unidentified source, and Kevin Beaumont verified multiple victims. Leaked data included cloud and AI keys, repository and package tokens, SSH and Kubernetes secrets, environment variables, database passwords, GitLab and GitHub PATs, and Salesforce, Slack, and Microsoft Azure credentials.

High-confidence victims included Nvidia, AWS, Samsung Electronics, samsung.com, Salesforce, Cisco, Roche, ServiceNow, Siemens AG, S&P Global, Airbus US Space & Defense, John Deere, Regeneron, LSEG, Thomson Reuters, FedEx, Munich Re's remunichre.com, MediaTek, Volkswagen, Deloitte, Kroger, Siemens Energy, Thales, X, Zscaler, Epic Games, Orange, HP, Philips, Fortum, Vodafone, Carl Zeiss, Deutsche Bahn, NGINX, BT, Liebherr, Krungthai Bank, and Roku. An @siriusxm.com address instead traced to subsidiary AdsWizz.

The TeamPCP gang, reportedly composed largely of teenagers, claimed the campaign, and researchers largely corroborated it. The operation originated with a Trivy compromise and also infected KICS and the Telnyx Python SDK. CloudSEK said Trivy developers rotated but did not fully revoke an automation token for 20 days, allowing malicious force-pushes to third-party builds. Researchers advise auditing for both LiteLLM versions, treating every accessible secret as compromised, revoking and rotating credentials, and reviewing logs and egress controls.

Positives

  • CloudSEK and Hudson Rock identified the 40-minute March exposure and published high-confidence victim findings.
  • Kevin Beaumont independently verified sensitive data belonging to multiple victim organizations.
  • Researchers largely corroborated TeamPCP's claim, strengthening attribution for the four-package campaign.
  • Hudson Rock issued specific guidance covering LiteLLM versions 1.82.7 and 1.82.8, credential revocation, logging, and egress audits.

Risks & concerns

  • Compromised LiteLLM releases exposed millions of secrets from roughly 434,000 CI/CD pipelines during only 40 minutes.
  • More than 2,500 organizations may face unauthorized access involving cloud keys, database passwords, tokens, and other credentials.
  • Many active secrets lack company domains or internal identifiers, leaving an unknown number of organizations unaware of their exposure.
  • Trivy's incompletely revoked automation token allowed attackers to force-push malicious code into third-party builds for 20 days.
  • LiteLLM, Trivy, KICS, and the Telnyx Python SDK were all infected through the broader supply-chain campaign.
  • Hudson Rock obtained the 195TB source file without identifying where the information originated.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate