The LiteLLM supply chain attack this year could be the biggest ever
7 Articles
7 Articles
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
Terabytes of credentials, many of them belonging to the world's largest and most sensitive organizations, have been exposed in an attack on the supply chain against LiteLLM, an open source tool that accelerates the development of software powered by AI. Microsoft, Amazon, Cisco, Samsung and Salesforce are just some of the entities whose access secrets have been exposed.tags: attack, chain, supplies, credentials, filtered, litellm» original news …
A supply chain attack launched at the end of March appears to have significantly greater effects than was initially known.
In PyPI introduced LiteLLM versions stole access data and tokens. CloudSEK identifies potential affected persons of the TeamPCP campaign. In the PyPI package management two compromised versions of the Open Source software LiteLLM (1.82.7 and 1.82.8) were released at the end of March 2026. LiteLLM serves as an AI gateway to connect different language models. The manipulated packages were active for about 40 minutes before PyPI quarantined them. V…
An attack on LiteLLM’s supply chain exposes terabytes of credentials from 2,500 organizations, including Microsoft and Amazon. Keys of the operation The track was Python’s official repository. Victims downloaded manipulated versions of LiteLLM from PyPI, the legitimate packet channel. Over 2,500 organizations were exposed. CloudSEK and Hudson Rock rank among those affected by Microsoft, Amazon, Cisco, Samsung and Salesforce. The theft was comple…
The LiteLLM supply chain attack this year could be the biggest ever
More than 2,500 organizations were exposed in the LiteLLM supply chain attack earlier this year, according to CloudSEK, making it the biggest-ever supply chain attack.The company said a host of major organisations, including Nvidia, Samsung, Cisco, ServiceNow, Zscaler, and more were exposed. The company stressed that this isn’t proof they were actually compromised, however. Information exposed in the campaign included AWS, Google Cloud, and Micr…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium









