Dossier · Ongoing
The LiteLLM supply chain attack
From the compromised scanner in March to the 153-gigabyte data archive in August: the LiteLLM attack and its fallout, tracked over time.
In March 2026, the group TeamPCP compromised the security scanner Trivy and used it to inject malicious code into two versions of the AI gateway LiteLLM, which were briefly available on PyPI. Five months later, new analyses reveal the true scope: CloudSEK first put the number of affected companies above 2,500 in mid-August, then security firm Hudson Rock released the underlying 153-gigabyte raw data archive along with further affected corporations.
This dossier tracks how the attack and its fallout continue to unfold – from newly identified companies to maintainer responses and warnings from investigators.