2,500+ companies.
434,000 CI/CD pipelines.
One compromised AI package.
CloudSEK just published the full victim list from the LiteLLM supply chain attack — and the names will keep you up tonight.
AWS. Cisco. Deloitte. Volkswagen. Samsung. S&P Global. FedEx. X Corp. Siemens. ServiceNow.
All potentially exposed.
Here's how it happened:
A threat actor group called TeamPCP compromised Trivy — a security scanner that thousands of CI pipelines trust.
That poisoned scanner flowed into LiteLLM's build process.
Two malicious PyPI releases went live.
A .pth file executed at Python startup. No import required. No user action needed.
Every CI runner that installed those versions had its credentials silently harvested.
Cloud keys. Repository tokens. Kubernetes secrets. LLM API keys.
The attacker scraped /proc/<pid>/mem to extract secrets GitHub Actions tries to mask.
Then encrypted everything with AES-256 under a hard-coded RSA-4096 key.
The FBI issued FLASH advisory FLASH-20260702-01 in July. The threat is still live.
This is not a software bug. This is a new attack surface.
AI infrastructure sits at the junction of data, identity, compute, and autonomous action.
Compromise the AI layer and you own everything connected to it.
Audit your AI dependencies today. Pin every package to a verified hash. Rotate every credential your CI runners can read.
If you use LiteLLM, assume you are exposed until proven otherwise.
SOURCE: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
VERIFIED: CloudSEK research report (Aug 11, 2026), FBI FLASH advisory FLASH-20260702-01, Unit 42 analysis, Sophos threat report
SIGNAL: AI supply chains are now the primary attack vector. Every enterprise running AI workloads in CI/CD needs to audit their dependency chain immediately.
2,500 companies just had their AI infrastructure exposed. The FBI is involved. Your CI/CD pipeline is likely next.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments