< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 9 sources · 5 days · First seen · Last updated

LiteLLM supply chain attack

Overview

A software supply chain attack targeted LiteLLM, an open-source AI gateway, potentially exposing credentials for over 2,500 organizations. The breach occurred when attackers compromised the release process for the Trivy scanner, allowing poisoned code to enter the LiteLLM build pipeline and produce malicious packages on the Python Package Index (PyPI).

Malicious versions 1.82.7 and 1.82.8 were available for a limited window, with some researchers suggesting the impact may have spanned approximately five days. The malware was designed to steal sensitive data, including cloud keys, SSH keys, Kubernetes tokens, database passwords, and LLM API keys for services like OpenAI and Anthropic. The attack's reach extended to organizations using AI agent frameworks such as CrewAI, DSPy, and MLflow, as LiteLLM serves as a core dependency for these tools.

Analysts have attributed the campaign to the group TeamPCP (also tracked as UNC6780). While major entities such as NVIDIA, Cisco, and Volkswagen were identified as potentially affected, researchers noted that exposure does not confirm a successful breach for every named organization. Experts advise affected parties to rotate all credentials immediately.

Entities

TeamPCP · LiteLLM · CloudSEK · Google · Python Package Index

Timeline

  1. 2 days ago

    [TECHNOLOGY] 3 sources
    LiteLLM supply chain attack exposes credentials for 2,500+ organizations

    A supply chain attack on LiteLLM has potentially exposed credentials and CI/CD data for over 2,500 organizations, affecting various AI agent frameworks and cloud service keys.

  2. 7 days ago

    [TECHNOLOGY] 6 sources
    LiteLLM supply chain attack potentially exposes 2,500 companies

    A supply chain attack on LiteLLM via a compromised Trivy component may have exposed 2,500 organizations and 434,000 CI/CD pipelines to credential theft.

Sources

cyberinsider.com · cybernoz.com · cybersecuritynews.com · dev.to · enterprisesecuritytech.com · nouvelles-du-monde.com · sciencepost.fr · thehackernews.com · unite.ai