Dossier · Ongoing

The LiteLLM supply chain attack

From the compromised scanner in March to the 153-gigabyte data archive in August: the LiteLLM attack and its fallout, tracked over time.

In March 2026, the group TeamPCP compromised the security scanner Trivy and used it to inject malicious code into two versions of the AI gateway LiteLLM, which were briefly available on PyPI. Five months later, new analyses reveal the true scope: CloudSEK first put the number of affected companies above 2,500 in mid-August, then security firm Hudson Rock released the underlying 153-gigabyte raw data archive along with further affected corporations.

This dossier tracks how the attack and its fallout continue to unfold – from newly identified companies to maintainer responses and warnings from investigators.

Timeline

  1. LiteLLM attack hits over 2500 companies worldwide

    A compromised scanner opened the door to the open AI gateway LiteLLM in March – a new report shows the extent of the stolen credentials.

  2. LiteLLM Leak: Hudson Rock Finds 153-Gigabyte Archive of Credentials

    Hudson Rock analyzes a 153-gigabyte data archive from the March attack and names additional global corporations as potential targets.