Updated
Updated · Ars Technica · Aug 12
TeamPCP Supply-Chain Attack Exposes 434,000 CI/CD Credentials via LiteLLM in 40 Minutes
Updated
Updated · Ars Technica · Aug 12

TeamPCP Supply-Chain Attack Exposes 434,000 CI/CD Credentials via LiteLLM in 40 Minutes

3 articles · Updated · Ars Technica · Aug 12

Summary

  • 434,000 CI/CD pipelines had credentials exposed after organizations ran compromised LiteLLM packages from PyPI during a 40-minute window in March, according to CloudSEK and Hudson Rock.
  • The tainted versions scraped memory from infected machines and exfiltrated cloud keys, repo tokens, SSH keys, Kubernetes secrets, package-publishing credentials and AI provider keys.
  • More than 2,500 organizations may be affected, with exposed secrets tied to major companies including Microsoft, Amazon, Cisco, Samsung and Salesforce, though some identities in the dump were initially hard to verify.
  • Hudson Rock said it analyzed a 195TB file to uncover the breach, while independent researcher Kevin Beaumont said he confirmed the leaked data was legitimate across multiple victim organizations.
  • Researchers said the LiteLLM compromise stemmed from an earlier supply-chain attack on Trivy; KICS and the Telnyx Python SDK were also infected in the campaign claimed by TeamPCP.

Insights

If traditional security missed the LiteLLM attack, what other malicious code is silently scraping memory in your AI pipelines right now?
How did a 40-minute open-source breach in March 2026 expose the deepest secrets of tech giants like Microsoft and Amazon?
Could the rush to adopt open-source AI tools be creating a catastrophic cybersecurity blind spot for thousands of global organizations?