TeamPCP Supply-Chain Attack Exposes 434,000 CI/CD Credentials via LiteLLM in 40 Minutes
Updated
Updated · Ars Technica · Aug 12
TeamPCP Supply-Chain Attack Exposes 434,000 CI/CD Credentials via LiteLLM in 40 Minutes
3 articles · Updated · Ars Technica · Aug 12
Summary
434,000 CI/CD pipelines had credentials exposed after organizations ran compromised LiteLLM packages from PyPI during a 40-minute window in March, according to CloudSEK and Hudson Rock.
The tainted versions scraped memory from infected machines and exfiltrated cloud keys, repo tokens, SSH keys, Kubernetes secrets, package-publishing credentials and AI provider keys.
More than 2,500 organizations may be affected, with exposed secrets tied to major companies including Microsoft, Amazon, Cisco, Samsung and Salesforce, though some identities in the dump were initially hard to verify.
Hudson Rock said it analyzed a 195TB file to uncover the breach, while independent researcher Kevin Beaumont said he confirmed the leaked data was legitimate across multiple victim organizations.
Researchers said the LiteLLM compromise stemmed from an earlier supply-chain attack on Trivy; KICS and the Telnyx Python SDK were also infected in the campaign claimed by TeamPCP.