Skip to content
Blog Post

From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack

InfoStealers
7 min read
From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack

From CI Pipeline to Ransomware Leak Site: 6 High-Profile Breaches in the LiteLLM Attack

By the Hudson Rock Threat Intelligence Team

Following our initial report detailing the largest AI supply chain breach of the year, Hudson Rock’s threat intelligence team has continued to analyze the catastrophic fallout of the LiteLLM and Trivy supply chain campaign. As part of our global ethical disclosure efforts, we have reconstructed the attack paths likely used by threat actors to compromise enterprise environments worldwide.

A Critical Note on Blame: It is highly important to emphasize that these breaches were extremely difficult to avoid. The affected organizations are not at fault. This sophisticated supply chain compromise exploited deep, trusted dependencies within standard DevOps pipelines, successfully bypassing traditional security perimeters.

This blog serves as an urgent call to action. Our goal is not to point fingers, but to provide transparency and urge companies to claim their ethical disclosures and lock down their environments before this exfiltrated data begins to circulate more heavily among opportunistic cybercriminals.

The LiteLLM/Trivy data gives us rare and terrifying insight into how organizations suffered devastating ransomware attacks lately. By analyzing the compromised CI runner dumps, we can map exactly what the threat actors likely obtained before launching their extortion campaigns.

Global Ethical Disclosures: Over the last few days, Hudson Rock has completed over 250 ethical disclosures to organizations worldwide, working tirelessly to alert enterprises to their exposed cloud infrastructure before threat actors could weaponize the data. Additionally, we have provisioned the intelligence data directly to our cybersecurity partners so they can immediately protect their own customers.

📊 The Blast Radius: By the Numbers

We disclosed compromised CI/CD pipelines, live cloud keys, and API tokens to over 250 global enterprises, including 30+ S&P 500 and Global Fortune 500 companies across every critical sector:

Technology & Cloud
Telecommunications
Automotive & Industrial
Government & Research
Retail & Logistics
Healthcare & Life Sciences
Consulting & Finance

Below, we deep dive into the high-profile organizations compromised in this campaign and detail the exact secrets, tokens, and configurations that likely fueled downstream extortion by groups like Vect ransomware (TeamPCP).

Vect Ransomware Leak Site showing S&P Global and Guesty
Vect ransomware group leak site tracking the TeamPCP LiteLLM/Trivy campaign victims. These harvested credentials directly fueled downstream extortion. Both organizations are now actively listed on leak sites. (Image via www.ransomware.live)

1. Guesty

The Breach: The property management software company Guesty suffered a direct hit to their critical cloud infrastructure. As seen on the leak sites above, this data was quickly weaponized for extortion.

How Hackers Likely Got In: Based on our analysis of the compromised CI runner dumps and public reports, it is assessed that threat actors likely gained access to critical cloud infrastructure, specifically exposing dozens of AWS Access Keys and secrets directly from Guesty’s CI pipelines. The raw pipeline logs dumped the credentials in plain text, which likely granted the attackers administrative access to their cloud environments.

Outcome of the Breach: According to the Vect ransomware group, the data stolen from Guesty includes internal projects, 4 million sent/received emails with attachments, their entire userbase, and highly sensitive Airbnb and Booking.com integration data. The total data size extorted is reported to be 700GB.
Guesty CI Runner dump showing AWS and Kubernetes secrets
Compromised CI runner dumps for Guesty.com revealing exposed AWS and Kubernetes secrets.

2. S&P Global

The Breach: For S&P Global, the blast radius of this supply chain attack is massive. Like Guesty, S&P Global’s harvested credentials directly fueled downstream extortion and resulted in them being listed on the Vect ransomware group’s leak site.

How Hackers Likely Got In: Evidence suggests threat actors likely intercepted temporary AWS STS session tokens and long-lived AWS keys during a terraform-actions workflow. The sheer volume of exposed data is staggering: judging by the telemetry, attackers likely accessed thousands of secrets, GitHub tokens, JWTs, and RSA private keys, fundamentally compromising their internal repository and cloud security architecture.

Outcome of the Breach: According to the Vect ransomware group leak site, the threat actors successfully exfiltrated 250GB of highly confidential data, including internal projects, core architectural secrets, and active API keys.
S&P Global Secrets Overview
Overview of the thousands of secrets extracted from S&P Global’s infrastructure inside Hudson Rock’s Cavalier portal.
S&P Global CI Runner Dump
Deep dive into the S&P Global runner environments, showing GitHub tokens and ECR repository URLs exposed.

3. Cisco

The Breach: Cisco’s source code was stolen in a breach linked directly to a compromised development environment running a poisoned Trivy container. The attackers likely infiltrated critical repositories, including cisco-it-cloud-infrastructure.

BleepingComputer article on Cisco breach
Public reporting via BleepingComputer confirming the Cisco source code theft via the Trivy-linked breach.

How Hackers Likely Got In: Judging by the environment dumps, it appears the attackers likely scraped GitHub Personal Access Tokens (PATs) and highly sensitive API keys from the runner’s environment variables. The exposure of an Artifactory token likely allowed access to internal packages, while a Conjur API key appears to have provided a foothold into Cisco’s broader secret management infrastructure.

Cisco GitHub Actions config
Cisco GitHub Actions runner environment dump showing the compromised Trivy action path and internal repository links.
Cisco Secrets Dump
Exfiltrated environment configuration from Cisco revealing highly sensitive Conjur, GitHub, and JIRA secrets.

4. European Commission

The Breach: The European Commission suffered a severe cloud breach resulting from this campaign. The compromised runner was executing a Terraform deployment for AWS infrastructure.

CERT-EU Press Release
Public statement via CERT-EU regarding the cybersecurity incident affecting the europa.eu AWS infrastructure.

How Hackers Likely Got In: Telemetry indicates attackers likely obtained AWS IAM credentials directly from the environment, granting administrative cloud access. Furthermore, a hardcoded SSH private key and GitLab CI tokens appear to have been exposed, which would likely allow the threat actors to pivot laterally across the European Commission’s GitLab infrastructure.

European Commission GitLab Runner variables
Raw exfiltrated log from the European Commission breach highlighting exposed AWS access keys and GitLab tokens.

5. Mercor

The Breach: Mercor, a $10 billion AI startup, faced a catastrophic security incident impacting their AI annotation and RL Studio platform resulting from the LiteLLM supply chain attack.

Mercor Security Incident Update
Mercor’s public update confirming they were affected by the LiteLLM supply chain attack.

How Hackers Likely Got In: Based on the data, it appears attackers likely exfiltrated local configuration files and runner environment variables. This would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.

Mercor Compromised Secrets in Cavalier
Hudson Rock Cavalier view showing the exact compromised Mercor environment variables, including Anthropic, Linear, and Datadog API keys inside Cavalier (secrets blurred for safety).
Outcome of the Breach: The fallout for Mercor has been monumental. According to available reports, attackers moved laterally through Mercor’s systems and extracted approximately 4 Terabytes of data. This included 939 GB of proprietary source code, potential AI training methodologies, video interviews, and user database records containing the Social Security numbers and biometric data of over 40,000 contractors. Meta subsequently paused a major data contract, and multiple class-action lawsuits have been filed.
Lapsus$ Statement on Mercor Data
The Lapsus$ extortion group claiming to have permanently sold the entirety of Mercor’s biometric, PII, and AI training data to Chinese enterprises.

6. Telnyx

The Breach: Telecom and communications platform Telnyx was breached through their internal infrastructure via malicious Python SDK packages tied to the broader campaign.

Telnyx Security Advisory
Telnyx advisory detailing the malicious SDK versions linked to the Trivy/LiteLLM campaign.

How Hackers Likely Got In: According to the data dumps, it is assessed that attackers likely recovered Docker configuration files containing base64-encoded basic authentication credentials and GitHub PATs. This would have allowed threat actors to pull and push directly to Telnyx’s internal production and development container registries.

Telnyx Secrets in Cavalier
Hudson Rock Cavalier view displaying the exfiltrated Docker configuration and GitHub tokens from Telnyx’s environment (secrets blurred for safety).
Outcome of the Breach: On March 27, 2026, two unauthorized versions of the Telnyx Python SDK (4.87.1 and 4.87.2) were published to PyPI containing malicious credential-stealing code. Telnyx publicly confirmed the incident, clarifying that while the PyPI distribution channel was compromised, the Telnyx platform, APIs, customer data, and voice/messaging infrastructure itself were not compromised.

🚨 Free Look-Up Tool for Affected Organizations

Because of the critical nature of this massive campaign, Hudson Rock is committed to performing ethical disclosures for affected organizations.

We have launched a dedicated portal where companies can verify if their domains are part of this compromised dataset. Following confirmation of impact, organizations can reach out directly through the tool to receive a full ethical disclosure regarding their exposure.

Hudson Rock LiteLLM Look-Up Tool Dashboard

At Hudson Rock, we’ve wrapped up our direct ethical disclosures for affected enterprises and have just provisioned the intelligence data directly to our cybersecurity partners so they can immediately protect their own customers.

Search Your Domain Now

Continue reading

Related articles

Free Tools Check your exposure