Close Menu
NCIJ Network NCIJ Network
    What's Hot

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    August 12, 2026

    Binance Denies Plans to Drop RedotPay Case in Singapore

    August 12, 2026

    Sharks on a Plane – Inside Climate News

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges
    • Binance Denies Plans to Drop RedotPay Case in Singapore
    • Sharks on a Plane – Inside Climate News
    • Seven Borr Drilling rigs find more work in Asia, Europe, and Africa
    • General Dynamics Failed to Build Artillery Shells for the Army — ProPublica
    • France’s complex picture of collaborating with and combating Nazis | Second world war
    • Wisconsin Democrats choose moderate Crowley for governor’s race in US battleground state
    • Die neue Weltordnung der AfD – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 2,500 organizations and over 430,000 CI/CD pipelines were affected by the LiteLLM supply chain attack earlier this year, CloudSEK reports.

    The LiteLLM compromise was disclosed shortly after the supply chain attack on Aqua Security’s Trivy open source vulnerability scanner and was a direct result of it.

    According to CloudSEK, TeamPCP, the threat actor behind multiple high-profile open source software (OSS) compromises, never targeted LiteLLM directly.

    The open source Python library and proxy server was compromised after its CI pipeline installed the compromised Trivy version automatically. Two LiteLLM versions, namely 1.82.7 and 1.82.8, were pushed to PyPI, providing the hackers with access to all the information LiteLLM touched.

    “Trivy, then the [LiteLLM] build system, then the LiteLLM release: one unrevoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure,” CloudSEK notes.

    “Automated build systems compress time. Once a malicious artifact reaches a registry, scheduled jobs, dependency resolvers, ephemeral runners, developer laptops, and cached layers can copy it rapidly. The forensic and credential-rotation window therefore extends beyond package removal,” the company continues.

    Advertisement. Scroll to continue reading.

    The modified LiteLLM versions contained malicious code executed on every Python invocation, with no explicit import. The payload ran on all systems where the package was installed.

    According to CloudSEK, while the affected packages were live for only 40 minutes, the window was long enough for the malicious code to propagate, ultimately exposing 434,000 CI/CD pipelines and impacting over 2,500 organizations.

    Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Accenture Federal Services, Siemens, Regeneron Pharmaceuticals, London Stock Exchange Group, FedEx, Volkswagen, Orange, HP, Deutsche Bahn, NGINX, and Zscaler are only some of the names on CloudSEK’s list.

    “The 2,500+ company and 434,000 pipeline figures describe reconstructed exposure. They should not be read as proof that every listed organization was successfully compromised or that every credential was stolen,” CloudSEK says, noting that compromise should be independently verified in each case.

    The LiteLLM supply chain attack led to broad sensitive information compromise: package publishing credentials, cloud keys, SSH keys, tokens, environment variables, runtime data, and AI provider keys, among others.

    Hackers could use these secrets to take over accounts, steal data, inject malicious commits, achieve persistence, move laterally, disrupt services, deploy malware, and mount various other types of attacks.

    Organizations should consider any secret accessible to the LiteLLM library as compromised, including those “present in process memory, injected into the job, stored on disk, or retrievable through an instance metadata service”.

    Potentially compromised secrets should be validated, then rotated alongside service accounts and sessions, and logs should be reviewed to determine the exposure scope and timeframe.

    According to CloudSEK, the next major supply chain attack will likely target AI infrastructure, as these systems have become “high-value junctions between data, identity, compute, and autonomous action”.

    “The incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else,” CloudSEK notes.

    Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    Related: New GitHub, PyPI Policies Boost Supply Chain Security

    Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

    Related: More Klue Breach Victims Identified as Hackers Get Hacked

    attack chain Impacted LiteLLM Organizations supply
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    Microsoft releases Windows 10 KB5120249 extended security update

    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    August 12, 2026

    Binance Denies Plans to Drop RedotPay Case in Singapore

    August 12, 2026

    Sharks on a Plane – Inside Climate News

    August 12, 2026

    Seven Borr Drilling rigs find more work in Asia, Europe, and Africa

    August 12, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    August 12, 2026

    Binance Denies Plans to Drop RedotPay Case in Singapore

    August 12, 2026

    Sharks on a Plane – Inside Climate News

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.