Skip to content
Blog Post

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure

InfoStealers
6 min read
Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure

The cybersecurity landscape is currently reeling from one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. Orchestrated by a threat actor group known as “TeamPCP,” this cascading attack ultimately compromised LiteLLM – a widely adopted open-source AI proxy gateway – leading to the silent exfiltration of deep developmental secrets from thousands of continuous integration and continuous deployment (CI/CD) pipelines worldwide.

The Mechanics of the Attack: From Poisoned Scanner to AI Gateway

Excellent forensic research published by Snyk, Trend Micro, and Cycode has thoroughly detailed the mechanics of this breach. The attack did not begin with LiteLLM. Instead, TeamPCP first compromised the GitHub Actions pipeline for Trivy, a highly popular open-source vulnerability scanner.

Because the developers of LiteLLM utilized Trivy in their own CI/CD pipeline, the poisoned security scanner was granted legitimate read access to their runner environment. This allowed the attackers to silently exfiltrate LiteLLM’s PyPI publishing tokens. Armed with these credentials, TeamPCP published malicious versions of the package (1.82.7 and 1.82.8).

The payload delivery was exceptionally stealthy. By utilizing a .pth Python startup hook, the malicious code executed the moment the Python interpreter initialized – regardless of whether the LiteLLM library was explicitly imported. The three-stage payload immediately began harvesting environment variables, local configuration files (like .kube/config and .aws/credentials), attempted lateral movement across Kubernetes clusters, and installed a persistent systemd backdoor.

The 153GB Raw Database Surfaces

While the security community has deeply analyzed the malware’s behavior, Hudson Rock has independently obtained the actual fallout: the raw exfiltrated data. This provides an unfiltered look into the massive scale of the compromise through the actual, raw files.

Our researchers have obtained and analyzed a staggering 153GB RAR archive. This massive corpus contains exactly 433,909 files. Through our analysis, we have successfully attributed 118,829 CI runner dumps to 2,488 affected corporate domains. Whenever a developer machine, production server, or CI/CD pipeline executed the compromised LiteLLM package, the threat actors successfully harvested the live environment memory and configurations mid-execution.

GitLab User Email Aggregation Figure 2: An aggregation of several enterprise environment dumps revealing the GITLAB_USER_EMAIL variable, directly attributing the leaked pipelines to major global organizations like Orange, Boeing, and Roku.
Exposed AWS Secrets Figure 3: Widespread exposure of cloud infrastructure keys, including AWS_SECRET_ACCESS_KEY and environment-specific secrets like WORKLOADS_DEV_AWS_SECRET, dumped in plain text.
Various API Secrets and Tokens Figure 4: A trove of internal corporate secrets, exposing sensitive tokens for platforms such as Salesforce (SALESFORCE_CLIENT_SECRET), Slack (SLACK_SIGNING_SECRET), and Microsoft Azure environments.
Exposed AI API Keys Figure 5: Exposed AI provider API keys captured mid-execution, giving attackers direct access to the victim’s LLM routing infrastructure and billing quotas.

The Attribution Challenge & The Unattributed Secrets Problem

Identifying the victims within this 153GB database presents a unique threat intelligence challenge. Accurate attribution requires looking past the surface level to analyze the actual infrastructure boundaries.

For example, in one high-profile compromise within the dataset, the committer email associated with the pipeline run belonged to @siriusxm.com. However, when examining the broader context of the environment dump – specifically the self-hosted infrastructure endpoints like CI_SERVER_FQDN=gitlab.adswizz.com and registry.adswizz.com – it becomes clear that the breach occurred within the infrastructure of AdsWizz (a subsidiary of SiriusXM). Threat intelligence teams must rely on these hard infrastructure markers rather than simple committer emails to correctly identify the operational target and route alerts to the correct SOC teams.

However, a vast number of files in this leak contain highly sensitive secrets but completely lack clear organizational attribution.

Many CI/CD pipelines are configured generically. The dumped variables contain active database passwords, third-party API keys, and cloud credentials without any identifiable company email, custom domain string, or internal server name. This means countless organizations currently have active secrets sitting in this database, completely unaware of their exposure.

Secrets with no organizational attribution Figure 6: Highly sensitive database and infrastructure secrets dumped from runners lacking clear organizational attribution, leaving companies entirely blind to their exposure.

Notable Impacted Organizations

We acknowledge the excellent initial victim tracking published by CloudSEK. Our independent analysis of the raw, unredacted data confirms the staggering scale of this compromise, mapping 118,829 attributed pipeline runs to nearly 2,500 distinct organizations. Some of the most notable impacted entities include:

Organization Domain
Amazon Web Services (AWS) amazon.com
Samsung Electronics samsung.com
Cisco Systems, Inc. cisco.com
Salesforce, Inc. salesforce.com
ServiceNow servicenow.com
S&P Global spglobal.com
Siemens AG siemens.com
John Deere deere.com
Deloitte deloitte.com
Epic Games epicgames.com
Orange S.A. orange.com
TomTom tomtom.com
BT Group bt.com

Native Integration into Cavalier Threat Intelligence

To provide actionable intelligence to our partners and affected entities, the complete 153GB dataset has been natively integrated into Cavalier, Hudson Rock’s threat intelligence platform. Existing customers can immediately query their domains to view exposed runner dumps, automatically categorized secrets, and associated committer identities.

Furthermore, organizations that verify their impact through our look-up tool and complete the ethical disclosure process will receive access to view their specific leaked data directly within the platform to aid in their incident response efforts.

Hudson Rock Cavalier Domain Overview for Samsung Figure 7: Cavalier’s domain overview dashboard highlighting the newly integrated “LiteLLM Compromised” intelligence flag, instantly alerting organizations to their exposure within the massive supply chain dataset alongside other known vulnerabilities.
Hudson Rock Cavalier Dashboard showing Samsung LiteLLM leaks Figure 8: Hudson Rock’s Cavalier platform showcasing the parsed LiteLLM dataset. In this example attributed to Samsung, the platform automatically categorizes 17 compromised pipeline dumps exposing hundreds of sensitive assets, including Bitbucket deployment tokens, Elastic API keys, internal JWTs, and NPM tokens.

Immediate Remediation Guidance

If your organization utilizes AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages, you must immediately audit your environment for versions 1.82.7 and 1.82.8 of LiteLLM. Immediate actions should include:

  • Aggressive Credential Revocation: Assume any secret accessible to your LiteLLM environment is compromised. Invalidate and rotate all AWS/GCP/Azure IAM keys, Kubernetes service account tokens, and GitLab/GitHub PATs.
  • Audit Logging & Egress Filtering: Review AWS CloudTrail and Kubernetes API audits for anomalous activity dating back to March 24, 2026. Implement strict network egress filtering on runner environments.
  • Inspect for Persistence: Check local development environments and containers for unauthorized `.pth` files in the site-packages directory, and look for suspicious systemd services (e.g., masquerading as “System Telemetry Service”).

🚨 Free Look-Up Tool for Affected Organizations

Because of the critical nature of this massive campaign, Hudson Rock is committed to performing ethical disclosures for affected organizations.

We have launched a dedicated portal where companies can verify if their domains are part of this compromised dataset. Following confirmation of impact, organizations can reach out directly through the tool to receive a full ethical disclosure regarding their exposure.

Hudson Rock LiteLLM Look-Up Tool Dashboard

At Hudson Rock, we’ve wrapped up our direct ethical disclosures for affected enterprises and have just provisioned the intelligence data directly to our cybersecurity partners so they can immediately protect their own customers.

Search Your Domain Now

Continue reading

Related articles

Free Tools Check your exposure