Skip to main content
See every side of every news story
Published loading...Updated

The LiteLLM supply chain attack this year could be the biggest ever

Summary by IT PRO
More than 2,500 organizations were exposed in the LiteLLM supply chain attack earlier this year, according to CloudSEK, making it the biggest-ever supply chain attack.The company said a host of major organisations, including Nvidia, Samsung, Cisco, ServiceNow, Zscaler, and more were exposed. The company stressed that this isn’t proof they were actually compromised, however. Information exposed in the campaign included AWS, Google Cloud, and Micr…
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

7 Articles

Terabytes of credentials, many of them belonging to the world's largest and most sensitive organizations, have been exposed in an attack on the supply chain against LiteLLM, an open source tool that accelerates the development of software powered by AI. Microsoft, Amazon, Cisco, Samsung and Salesforce are just some of the entities whose access secrets have been exposed.tags: attack, chain, supplies, credentials, filtered, litellm» original news …

A supply chain attack launched at the end of March appears to have significantly greater effects than was initially known.

In PyPI introduced LiteLLM versions stole access data and tokens. CloudSEK identifies potential affected persons of the TeamPCP campaign. In the PyPI package management two compromised versions of the Open Source software LiteLLM (1.82.7 and 1.82.8) were released at the end of March 2026. LiteLLM serves as an AI gateway to connect different language models. The manipulated packages were active for about 40 minutes before PyPI quarantined them. V…

An attack on LiteLLM’s supply chain exposes terabytes of credentials from 2,500 organizations, including Microsoft and Amazon. Keys of the operation The track was Python’s official repository. Victims downloaded manipulated versions of LiteLLM from PyPI, the legitimate packet channel. Over 2,500 organizations were exposed. CloudSEK and Hudson Rock rank among those affected by Microsoft, Amazon, Cisco, Samsung and Salesforce. The theft was comple…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT PRO broke the news on Thursday, August 13, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal