What happened
CloudSEK Threat Intelligence published a report on 2026-08-11 reconstructing full victim-exposure data from the March 2026 LiteLLM supply-chain attack, revealing the incident — originally disclosed as a narrow supply-chain compromise — actually exposed 2,500+ companies and approximately 434,000 CI/CD pipelines, making it one of the largest AI-infrastructure supply-chain breaches identified in 2026.
Why it matters
LiteLLM is a widely-adopted open-source AI gateway used to proxy calls across dozens of LLM providers; a compromise of it directly exposes the credentials and API keys organizations use to access OpenAI, Anthropic, and other providers, plus downstream CI/CD and cloud infrastructure. The scale disclosed here (2,500+ orgs, major tech companies named) is a material escalation of what was previously understood as a contained incident.
Attack vector
Threat actor group Team PCP compromised the Trivy open-source vulnerability scanner supply chain in March 2026, which cascaded into a compromise of LiteLLM's published packages; malicious LiteLLM versions distributed an information-stealing payload to any organization that installed them, harvesting cloud credentials, LLM provider API keys, source-code repository access, and Kubernetes environment secrets.
Affected systems
LiteLLM (open-source AI gateway/proxy) versions 1.82.7 and 1.82.8, compromised as a downstream consequence of the Trivy/Aqua Security supply-chain breach
Mitigation
Organizations that installed LiteLLM 1.82.7 or 1.82.8 must rotate all exposed credentials (cloud, LLM provider keys, CI/CD secrets) — package removal alone is insufficient per CloudSEK guidance; consult LiteLLM's official incident advisory.