CloudSEK Warns LiteLLM Supply Chain Attack May Have Exposed Thousands Of Organizations

CloudSEK Warns LiteLLM Supply Chain Attack May Have Exposed Thousands Of Organizations

CloudSEK has revealed new findings indicating that malicious LiteLLM releases linked to the TeamPCP supply chain attack may have exposed more than 2,100 organizations to credential theft. The compromised LiteLLM versions remained available on the Python Package Index for approximately 40 minutes in March 2026 and contained malicious code capable of stealing cloud credentials, SSH keys, Kubernetes tokens, database passwords, API keys, and other sensitive information from affected systems. According to CloudSEK, its assessment is based on a dataset containing approximately 434,000 files captured during the campaign, suggesting potential exposure across more than 2,500 organizations. The company emphasized that these figures do not represent confirmed victims but instead indicate organizations whose credentials or system information may have appeared in the collected data. To assist organizations in evaluating their potential exposure, CloudSEK has also launched a public lookup tool that allows searches by organization name or domain while assigning High or Medium confidence ratings based on available attribution evidence.

LiteLLM, an open source AI gateway that enables applications to connect with multiple artificial intelligence model providers, confirmed that versions 1.82.7 and 1.82.8 were compromised on March 24, 2026. The project advised users to treat any installation performed between 10:39 UTC and 16:00 UTC on that date as potentially affected. Investigators found that version 1.82.8 included a malicious Python startup file that executed automatically whenever Python started, regardless of whether LiteLLM itself was actively imported. The malware was designed to collect environment variables, SSH keys, Kubernetes tokens, cloud credentials, database passwords, and model API keys including OpenAI API keys and Anthropic API keys before encrypting and transmitting the stolen information to an attacker controlled domain. LiteLLM also warned that organizations may have installed the compromised versions indirectly through unpinned dependencies introduced by AI agent frameworks or orchestration tools, meaning some users could have been affected without intentionally installing the package.

Researchers linked the malicious LiteLLM releases to the wider TeamPCP supply chain campaign associated with the compromise of Aqua Security’s Trivy scanning tool. Google tracks the threat group behind the activity as UNC6780. According to published investigations, attackers retained access following incomplete credential rotation and later compromised Trivy repositories, publishing malicious software and modifying repository tags. The broader ecosystem compromise is tracked as CVE 2026 33634 and was added to CISA’s Known Exploited Vulnerabilities catalog during March 2026. While reports initially differed on how the malicious LiteLLM releases reached PyPI, CloudSEK explained that the published investigations describe different stages of the same attack chain. According to PyPA’s security advisory, attackers first obtained a PyPI publishing token through the compromised Trivy environment before using that credential to upload the malicious LiteLLM releases. CloudSEK also stated that it applies two independent attribution methods before identifying potentially affected organizations and withholds findings whenever those validation processes disagree.

The investigation also identified confirmed downstream impacts beyond the LiteLLM project itself. Checkmarx disclosed that credentials stolen during the Trivy campaign enabled unauthorized access to its GitHub repositories and resulted in the publication of malicious artifacts. Mercor also confirmed that it had been affected by the compromised LiteLLM releases, while CERT EU assessed with high confidence that a European Commission Amazon Web Services account had been compromised through the Trivy supply chain attack, leading to the exfiltration of approximately 91.7 gigabytes of compressed data. Security researchers and law enforcement agencies continue to advise organizations to review whether LiteLLM versions 1.82.7 or 1.82.8 were installed during the affected time window, immediately rotate all credentials that may have been accessible on those systems, and inspect GitHub environments for indicators associated with the TeamPCP campaign. The incident highlights the growing security risks facing open source AI software ecosystems, where compromised packages and dependency chains can expose sensitive infrastructure across thousands of organizations in a short period.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment