Meyka Pro banner
Law and Government

2,500 Organizations Hit by LiteLLM Supply Chain Attack in March

August 13, 2026
05:41 PM
4 min read

Key Points

2,500 organizations and 434,000 CI/CD pipelines exposed in March 2026 LiteLLM attack.

Malicious code ran for 40 minutes after TeamPCP compromised Trivy vulnerability scanner first.

Terabytes of cloud credentials, SSH keys, and AI provider tokens stolen from major tech companies.

Malicious open source packages rose 73% in 2026 as AI infrastructure becomes prime target.

Be the first to rate this article

A March 2026 supply chain attack on LiteLLM, a Python library with 95 million monthly downloads, exposed terabytes of credentials from over 2,500 organizations including Microsoft, Amazon, Cisco, and Samsung. Threat group TeamPCP compromised the Trivy vulnerability scanner first, then used that access to inject malicious code into LiteLLM versions 1.82.7 and 1.82.8. The poisoned packages exposed 434,000 CI/CD pipelines and stole cloud access keys, SSH credentials, and AI provider tokens.

How the attack unfolded

TeamPCP obtained a maintainer’s PyPI publishing credentials and pushed two malicious LiteLLM versions to the Python Package Index on March 24, 2026. The malicious code used a .pth file, a Python mechanism that auto-executes code every time the interpreter starts, requiring no explicit import. The packages remained live for only 40 minutes before removal, but that window was enough for the malicious payload to propagate across tens of thousands of corporate environments and cached systems.

The credential theft and cascading exposure

The malicious code accessed machine memory, scraped its contents, and exfiltrated cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, and AI provider keys. Security firm Hudson Rock analyzed a 195TB file containing the stolen data. Independent researcher Kevin Beaumont confirmed the data was legitimate and contained sensitive content from victim organizations. The breach exposed credentials across AWS, Google Cloud Platform, and Microsoft Azure environments.

Why AI infrastructure became the target

LiteLLM is a gateway tool that lets developers call over 100 large language model providers including Anthropic, Google Gemini, and AWS Bedrock. CloudSEK researchers noted that AI infrastructure is becoming a prime cyber target because these systems act as digital junctions where compromising one tool exposes identities and credentials across entire organizations. The attack was part of a broader TeamPCP campaign that also compromised Checkmarx’s KICS and the Telnyx Python SDK. Malicious open source packages rose 73% in 2026, according to ReversingLabs.

What organizations were exposed

Victims included Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Accenture Federal Services, Siemens, Regeneron Pharmaceuticals, London Stock Exchange Group, FedEx, Volkswagen, Orange, HP, Deutsche Bahn, NGINX, and Zscaler. The attack affected 434,000 CI/CD pipelines, the automated build systems that developers rely on to deploy code. CloudSEK warned that the forensic and credential rotation window extends beyond package removal because scheduled jobs, dependency resolvers, and cached layers can copy malicious artifacts rapidly.

Final Thoughts

The LiteLLM attack demonstrates how a single stolen credential can cascade through interconnected development tools, turning a 40-minute window into ecosystem-wide exposure affecting thousands of organizations. For Australian businesses using AI infrastructure, this highlights the need to audit Python package dependencies and rotate cloud credentials immediately.

FAQs

What is LiteLLM and why was it targeted?

LiteLLM is a Python library with 95 million monthly downloads that lets developers call over 100 large language model providers. It was targeted because it sits at a critical junction in AI development environments, exposing credentials across entire organizations when compromised.

How long were the malicious packages available?

The poisoned LiteLLM versions 1.82.7 and 1.82.8 remained on PyPI for approximately 40 minutes before removal, but that was enough time for the malicious code to propagate to tens of thousands of corporate environments.

What credentials were stolen in the LiteLLM attack?

Attackers stole AWS, GCP, and Azure cloud keys, SSH keys, repository tokens, Kubernetes secrets, package publishing credentials, and AI provider keys from infected machines.

Who is TeamPCP and why did they target open source tools?

TeamPCP is a threat group largely made up of teenagers that systematically compromised widely trusted open source security tools including Trivy and KICS before moving into AI infrastructure libraries on PyPI.

Disclaimer:

The content shared by Meyka AI PTY LTD is solely for research and informational purposes.  Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.

About Author

Author

Danny Kontos

Co Founder

Danny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.

What brings you to Meyka?

Pick what interests you most and we will get you started.

I'm here to read news

Find more articles like this one

I'm here to research stocks

Ask Meyka Analyst about any stock

I'm here to track my Portfolio

Get daily updates and alerts (coming March 2026)