LiteLLM Attack Affected 2,500 Companies, 434,000 CI/CD Pipelines: CloudSEK
The massive supply-chain attack that compromised LiteLLM in the spring affected more than 2,500 companies and exposed about 434,000 CI/CD pipelines, with victims ranging from top-tier IT and AI companies to cybersecurity firms, SaaS, and enterprises. It rolled up a lot of victims, but also was a high-profile example of the growing trend of threat […]
A massive supply-chain attack targeting LiteLLM, a gateway and toolkit for developers to call over 100 large language model (LLM) providers, affected more than 2,500 companies and exposed around 434,000 CI/CD pipelines in the spring. This attack, conducted by the threat group TeamPCP, was a result of compromising Aqua Security's Trivy open-source security vulnerability scanner and its associated GitHub Actions.
LiteLLM, which became part of a broader campaign, was compromised but never directly attacked. The chain of events, starting from the compromised Trivy scanner, led to the publication of malicious code on the Python Package Index (PyPI) in releases 1.82.7 and 1.82.8. The CloudSEK researchers noted that only 40 minutes were needed for the malicious packages to cause damage, with automated build systems accelerating the process.
Even after the packages were removed, the threat persisted, emphasizing the importance of early awareness for organizations to take preventive measures. Widespread compromise extended to top-tier IT, AI, cybersecurity firms, SaaS, and enterprises, including Nvidia, Intel, Zscaler, AWS, Cisco Systems, Salesforce, and ServiceNow. The FBI also issued an advisory highlighting the TeamPCP's compromise of supply chain entry points, including Trivy, LiteLLM, KICS, and the Telnyx Python SDK.
These tools were commonly integrated into enterprise development CI/CD pipelines, cloud infrastructure, and security workflows. The malware distributed by TeamPCP included CanisterWorm, SandClock, Mini Shai-Hulud, and Miasma, each designed to steal sensitive information such as cloud access tokens, API keys, and cryptocurrency wallet data.
The stolen data was encrypted and sent to typosquatted domains or uploaded as release assets in victim's GitHub accounts, leading to potential public disclosure of their secrets. The threat of AI infrastructure becoming a target of cybercriminals is expected to grow, as such systems become key junctions between data, identity, compute, and autonomous action.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.