LiteLLM Supply Chain Attack Exposed 2,500 Organizations and 434,000 CI/CD Pipelines, CloudSEK Finds

Super Daddy
3 Min Read

CloudSEK has published details of a supply chain attack that targeted LiteLLM, a widely used open-source AI gateway, in March 2026. The incident, attributed to threat actor group Team PCP, potentially exposed more than 2,500 organisations and approximately 434,000 CI/CD (continuous integration and continuous delivery/deployment) pipelines worldwide. CloudSEK describes it as the largest supply chain attack targeting AI infrastructure recorded in 2026.

LiteLLM Supply Chain Attack: Scope, Credentials, And Affected Organisations

The compromised LiteLLM packages were available through PyPI for approximately 40 minutes before removal – despite the short window, automated CI/CD environments can download and execute dependencies rapidly, meaning the exposure window may have been sufficient to create prolonged security risk across affected systems.

Among the information potentially accessible from affected environments were AWS, Google Cloud, and Microsoft Azure credentials, SSH keys, Kubernetes tokens, CI/CD secrets, repository credentials, environment variables, and LLM and API keys. CloudSEK’s exposure dataset includes high-confidence matches associated with NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales, and London Stock Exchange Group, among others.

CloudSEK notes that an exposure match does not automatically confirm successful compromise, data theft, or malicious use of credentials. Organizations identified in the dataset are advised to validate their exposure and investigate relevant systems. The United States’ Federal Bureau of Investigation (FBI) issued advisory FLASH-20260702-01 on 2 July 2026 covering Team PCP, separately flagging the group as an ongoing security concern.

The cybersecurity provider highlights that removing the compromised package does not invalidate credentials that were already copied from affected environments. Stolen access can potentially be reused, sold, or deployed in downstream attacks weeks or months after the original incident, which means the risk can go far beyond the initial compromise window.

The LiteLLM incident reflects a broader pattern identified by CloudSEK in which AI infrastructure (including AI gateways, MCP servers, agentic systems, and vector databases) sits between sensitive corporate data, cloud services, and systems capable of taking autonomous action; this positioning makes AI infrastructure an increasingly attractive target for threat actors seeking broad enterprise access rather than access to a single application.

Pokdepinion: The short window the malicious package was available shows how quickly automated pipeline environments can propagate a compromise before it is detected and removed.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *