Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organisations
Two malicious LiteLLM releases sat on PyPI for roughly 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens and database passwords. Threat intelligence firm CloudSEK says a dataset it obtained โ built from roughly 434,000 files scraped and exfiltrated from about 2,500 users of the compromised AI package โ has exposed gigabytes to terabytes of credentials and may affect 2,100+ organisations.
Key Facts
| Attribute | Detail |
|---|---|
| Vector | Malicious PyPI releases (LiteLLM, ~40 minutes exposure, March 2026) |
| Link | Associated with the earlier Trivy hack (access to trusted tooling release chain) |
| Harvested | Cloud keys, SSH keys, Kubernetes tokens, database passwords |
| Scope | ~434,000 files, ~2,500 package users, 2,100+ organisations potentially exposed |
| Confidence | Probable โ package-code analysis plus dataset corroboration; affected-org scope is an estimate |
Context
The incident is the sharpest example this week of attackers targeting the AI tooling and identity estate rather than endpoints: LiteLLM is a widely deployed AI gateway, so a poisoned release sits at a trusted position in the machine-learning supply chain. Ars Technica frames it as part of the ongoing TeamPCP credential-theft wave (see Long Running Data Theft Campaign Targeting Salesforce And Servicenow). Australian and NZ organisations running LiteLLM should audit installations and rotate secrets exposed during the affected window, consistent with ASD supply-chain guidance.
Related Pages
- Long Running Data Theft Campaign Targeting Salesforce And Servicenow โ SaaS credential theft
- 737 Chrome Vpn Extensions Caught Routing Traffic Through Single Proxy Infrastruc โ extension supply-chain abuse
Sources: raw/digests/Cyber-Digest-2026-08-13