Security researchers say a five-month-old supply-chain breach of the open-source LiteLLM project was larger than first understood, potentially exposing more than 2,500 companies and roughly 434,000 CI/CD pipelines to stolen credentials.
According to a report from threat-intelligence firm CloudSEK, the breach traces back to March, when a hacking group tracked as TeamPCP compromised Trivy, an open-source security scanner used inside LiteLLM's own build pipeline. The attackers exploited a Trivy authentication token that had been rotated after an earlier leak but never fully revoked, giving them roughly 20 days of quiet access before they used it to push malicious code.
A 40-minute window, months of exposure
Because LiteLLM's build system pulled in Trivy without pinning it to a verified version, the compromised scanner flowed straight into LiteLLM's own release process. The attackers used that access to publish two poisoned versions of the LiteLLM package, 1.82.7 and 1.82.8, to the Python Package Index. The malicious releases were live for about 40 minutes before being pulled, but that window was enough for the tainted packages to be pulled into thousands of downstream build systems, according to The Hacker News.
CloudSEK says organizations flagged with high confidence as exposed include Amazon Web Services, Cisco, Airbus and ServiceNow, alongside dozens of other firms spanning finance, telecommunications, manufacturing and defense. Data potentially harvested during the exposure window includes cloud access keys, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials and AI provider API keys — the kind of credentials that could let attackers move well beyond the original compromise.
The FBI issued a flash advisory in July warning that actors linked to the campaign are likely to weaponize harvested credentials over time, and that organizations exposed to the malicious packages should assume any secrets present during the window may still be usable unless they were rotated. Security researchers described the incident as a case study in how a single unrevoked token can create sweeping exposure across tools that trust one another by default.
LiteLLM has since patched its build pipeline, and CloudSEK is continuing to notify affected organizations directly. Security teams that use LiteLLM or depend on packages built through similar CI/CD chains are being urged to audit build logs from March, rotate any credentials that were active during the exposure window, and review which third-party tools their own pipelines pull in without version pinning.