TeamPCP Publishes Malicious LiteLLM Releases After Trivy Compromise, Exposing 2,488 Corporate Domains
Image: The Hacker News

TeamPCP Publishes Malicious LiteLLM Releases After Trivy Compromise, Exposing 2,488 Corporate Domains

12 August, 2026.Technology and Science.11 sources

Developing · updated 1h ago · 11 outlets

Two malicious LiteLLM releases on PyPI lasted about 40 minutes, exposing credentials. The attack impacted roughly 2,100–2,500 organizations, including Microsoft, Amazon, Samsung, Cisco.

11 outlets1 divide1 fact unevenly covered

Full story

LiteLLM credentials exposed

A supply-chain attack tied to LiteLLM exposed credentials and other sensitive data across thousands of corporate domains, with Help Net Security saying a massive 153GB archive surfaced after the LiteLLM incident and that Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains.

153GB archive stolen during the LiteLLM supply chain attack

Help Net SecurityHelp Net Security

Help Net Security reported that the breach had roots in an earlier compromise of Trivy, and that on March 19, 2026 TeamPCP used stolen credentials to publish a compromised version of Trivy.

Image from Ars Technica
Ars TechnicaArs Technica

In the LiteLLM build pipeline, Trivy was installed automatically, giving attackers read access to the runner environment and enabling them to steal the project’s PyPI publishing tokens.

Using those tokens, TeamPCP published two malicious LiteLLM releases—versions 1.82.7 and 1.82.8—to the Python Package Index on March 24.

Hudson Rock’s Alon Gal said, “We are leveraging this data for a global ethical disclosure effort,” framing the disclosure effort around enabling organizations to respond before threat actors weaponize the data publicly.

Scope, methods, and proof

CloudSEK told IT Pro that more than 2,500 organizations were exposed in the LiteLLM supply chain attack, while stressing the figures were not proof of confirmed compromise.

IT Pro said the exposed information included AWS, Google Cloud, and Microsoft Azure credentials, SSH keys, Kubernetes tokens, .env files and CI/CD secrets, and that malicious versions of LiteLLM were reportedly available through PyPI for just 40 minutes.

Image from DiarioBitcoin
DiarioBitcoinDiarioBitcoin

The Hacker News added that LiteLLM versions 1.82.7 and 1.82.8 were live on March 24 from 10:39 UTC for about 40 minutes before PyPI quarantined them, and that the project told users to treat any install that day up to 16:00 UTC as suspect.

The Hacker News also reported that version 1.82.8 included a file named litellm_init.pth that ran at Python interpreter startup, so it executed whenever a Python process started in the environment, whether or not anything imported LiteLLM.

Kevin Beaumont told Ars Technica, “I’ve confirmed the data is legit, by the way, multiple victim orgs,” describing the dataset as containing “a significant volume of sensitive content at orgs.”

What comes next

Researchers and security firms urged organizations to treat secrets accessible to the LiteLLM environment as compromised and to audit and rotate, with Help Net Security saying Hudson Rock urged organizations using AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for LiteLLM versions 1.82.7 and 1.82.8.

“This makes it a critical window of opportunity for companies to rotate keys and secrets before it eventually leaks

Help Net SecurityHelp Net Security

Help Net Security reported that Gal said, “This makes it a critical window of opportunity for companies to rotate keys and secrets before it eventually leaks,” while noting the data was “not leaked anywhere at the moment and is not circulating widely.”

The Hacker News said the FBI warned in a July 2 advisory, FLASH-20260702-01, that affiliated actors are likely to weaponize credentials exfiltrated during the TeamPCP campaign long after the initial compromise.

It also reported that the bureau’s guidance is scoped to credentials rather than to the package, and that a long-lived secret copied during the exposure window remains usable unless it has since been rotated or revoked.

CloudSEK’s Security Week summary said the 2,500+ company and 434,000 pipeline figures describe reconstructed exposure, and that organizations should independently verify each case rather than read the totals as proof of successful compromise.

Story read · 11 outlets · 1 disagreement · 1 fact unevenly covered

Coverage map

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Western Mainstream

Ars Technica
Ars Technica

Terabytes of credentials leaked in massive supply-chain attack

13 August, 2026

The Hacker News
The Hacker News

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

12 August, 2026

Other

Cybernews
Cybernews

Gargantuan trove of stolen secrets surfaces from LiteLLM supply chain attack

13 August, 2026

Help Net Security
Help Net Security

153GB of stolen credentials surface after LiteLLM supply chain attack

13 August, 2026

InfoStealers
InfoStealers

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Claim Your Ethical Disclosure

12 August, 2026

IT Pro
IT Pro

The LiteLLM supply chain attack this year could be the biggest ever

13 August, 2026

MONCLOA.COM
MONCLOA.COM

LiteLLM credential leak: a supply chain attack exposing terabytes of data from Microsoft and Amazon

13 August, 2026

SC Media
SC Media

LiteLLM supply chain attack impacted over 2,500 organizations

12 August, 2026

SecurityWeek
SecurityWeek

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

12 August, 2026

SOCRadar® Cyber Intelligence Inc.
SOCRadar® Cyber Intelligence Inc.

LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies

13 August, 2026

Western Alternative

DiarioBitcoin
DiarioBitcoin

Ataque a LiteLLM expone credenciales de Microsoft, Amazon y Samsung: 40 minutos que rompieron la cadena de suministro

13 August, 2026

NewsCord Digest

Get every Technology and Science story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Technology and Science