Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online
More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S.
<![CDATA[ <article> <ul><li><strong>More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM</strong></li><li><strong>LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner</strong></li><li><strong>Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed</strong></li></ul><p>Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.</p><p>LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy.</p><p>The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.</p><h2 id="an-attack-that-is-still-a-concern-nearly-five-months-later">An attack that is still a concern nearly five months later</h2><p>The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities.</p><p>The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.</p><p>The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.</p><p>These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there.</p><p>The victim-scale research <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank">done by CloudSEK</a> was further <a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" target="_blank">corroborated the following day by Hudson Rock,</a> and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.</p><p>The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said <a href="https://cyberplace.social/@GossiTheDog/117084861164567831" target="_blank">some of the compromised keys were still valid</a> after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. </p><p>CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running <a href="https://exposure.cloudsek.com/ai-supply-chain-incident" target="_blank">domain-lookup tools</a> so organizations can check their own exposure online.</p><p>Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.</p> </article> ]]>
Read the full article on TechRadar
Read Full Article →