← LiteLLM (BerriAI)

2026 LiteLLM — TeamPCP PyPI supply chain; researchers map ~2,488 firms / ~434K CI pipelines

2026 2.5K records affected Share on X

Data compromised

Researcher-mapped exposure across ~2,488 corporate domains and ~434,000 CI/CD pipeline runs: cloud credentials (AWS/GCP/Azure), Git PATs, SSH/Kubernetes secrets, package-publish tokens, env vars, LLM API keys. Not a consumer PII census — org/pipeline counts from CloudSEK / Hudson Rock analyses.

Technical writeup

Confirmed PyPI supply-chain compromise with August 2026 victim-scale research — TeamPCP compromised Trivy’s GitHub Actions path, stole LiteLLM publishing tokens, and shipped malicious LiteLLM 1.82.7–1.82.8. Payloads used Python .pth startup hooks and stealer tooling (SANDCLOCK per industry tracking) to harvest cloud keys, Git tokens, Kubernetes secrets, package credentials, env vars, and LLM API keys from CI runners and developer hosts; some exfil failed into public GitHub releases on victim accounts. LiteLLM published a March 2026 security update and removed malicious builds. CloudSEK later reconstructed exposure for 2,500+ organisations and ~434,000 CI/CD pipelines; Hudson Rock / Infostealers independently attributed 118,829 CI runner dumps in a ~153GB corpus to 2,488 corporate domains. FBI FLASH guidance cited in CloudSEK reporting warns harvested credentials may be reused after package removal. BreachHistory updates recordsAffected to 2488 as the researcher-attested corporate-domain count (not individual PII records) and keeps companyConfirmed true for the packaging incident.

Root cause

TeamPCP supply-chain attack: Trivy CI compromise → stolen PyPI publish tokens → malicious LiteLLM 1.82.7–1.82.8 with stealer payloads on CI/developer hosts

References