Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [incident, supply-chain, pypi, litellm, ai, credentials, malware, cloudsek] ยท confidence: medium ยท affected_sectors: [technology, ai, finance, government, healthcare] ยท au_impact: true

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organisations

Two malicious LiteLLM releases sat on PyPI for roughly 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens and database passwords. Threat intelligence firm CloudSEK says a dataset it obtained โ€” built from roughly 434,000 files scraped and exfiltrated from about 2,500 users of the compromised AI package โ€” has exposed gigabytes to terabytes of credentials and may affect 2,100+ organisations.

Key Facts

Attribute Detail
Vector Malicious PyPI releases (LiteLLM, ~40 minutes exposure, March 2026)
Link Associated with the earlier Trivy hack (access to trusted tooling release chain)
Harvested Cloud keys, SSH keys, Kubernetes tokens, database passwords
Scope ~434,000 files, ~2,500 package users, 2,100+ organisations potentially exposed
Confidence Probable โ€” package-code analysis plus dataset corroboration; affected-org scope is an estimate

Context

The incident is the sharpest example this week of attackers targeting the AI tooling and identity estate rather than endpoints: LiteLLM is a widely deployed AI gateway, so a poisoned release sits at a trusted position in the machine-learning supply chain. Ars Technica frames it as part of the ongoing TeamPCP credential-theft wave (see Long Running Data Theft Campaign Targeting Salesforce And Servicenow). Australian and NZ organisations running LiteLLM should audit installations and rotate secrets exposed during the affected window, consistent with ASD supply-chain guidance.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13