I
Agentic Intelligence · Infomly

2,500 companies just had their AI infrastructure exposed. The FBI is involved. Your CI/CD pipeline is likely next.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
153 gigabytes of stolen credentials sitting in a dataset that hasn't leaked yet.

434,000 CI/CD pipelines compromised.

2,488 corporate domains exposed — including NVIDIA, Microsoft, Cisco, Samsung, Siemens, FedEx, and Salesforce.

And the worst part: five months later, the stolen keys still work.

Here's what happened.

In March 2026, a threat group called TeamPCP compromised the Trivy vulnerability scanner. One unrevoked automation token. Three tools deep.

Trivy poisoned LiteLLM's build pipeline. LiteLLM published two backdoored versions to PyPI. Those versions were live for 40 minutes.

In that window, the malware ran on every Python invocation — not just when LiteLLM was imported. It harvested cloud IAM tokens, Kubernetes secrets, SSH keys, LLM provider API keys, and SaaS credentials from every pipeline that touched it.

Security researcher Kevin Beaumont tested credentials at a major US tech company that told him everything was rotated. Almost every one still worked.

The FBI issued a FLASH advisory in July. Sophos documented TeamPCP's formal partnership with ransomware affiliate VECT. Stolen LiteLLM credentials are now being converted into ransomware attacks across healthcare, financial services, and manufacturing.

This is not a dev tools problem. This is an AI infrastructure problem.

LiteLLM sits between your code and every LLM provider you use. When it was compromised, attackers didn't need to pivot to the crown jewels. LiteLLM was the crown jewels.

Audit every CI/CD pipeline that ran LiteLLM in March 2026 — even as a transitive dependency. Rotate every cloud IAM key, every AI provider API key, every Kubernetes token, every GitHub PAT. Assume the attacker already has them. Because right now, at least one major company thinks they rotated everything and they haven't.

SOURCE: https://www.techtimes.com/articles/324451/20260814/litellm-supply-chain-hack-hit-2488-firms-stolen-keys-still-work-five-months.htm
VERIFIED: SecurityWeek (Aug 12), TechTimes (Aug 14), CloudSEK (Aug 11), Hudson Rock (Aug 13), FBI FLASH-20260702-01
SIGNAL: Your AI infrastructure IS the supply chain attack surface. 2,500 companies learned this the hard way. The credentials are still live.
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.