2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026

2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026
CloudSEK says Team PCP leveraged a compromised security toolchain to push malicious LiteLLM releases in March 2026, creating a large supply-chain exposure across AI infrastructure and CI/CD environments. The incident potentially exposed cloud credentials, repository tokens, Kubernetes secrets, and AI provider keys at thousands of organizations, while FBI FLASH-20260702-01 warns the stolen access may still be weaponized. #TeamPCP #LiteLLM #Trivy #FBI FLASH-20260702-01

Keypoints

  • Team PCP is attributed with a major supply-chain attack that compromised LiteLLM-related build and release paths in March 2026.
  • CloudSEK reconstructed exposure data showing more than 2,500 companies and about 434,000 CI/CD pipelines potentially affected.
  • The malicious LiteLLM packages were live for about 40 minutes, but copied credentials could remain usable long after removal.
  • The stolen material included cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys.
  • The payload reportedly escalated to root on CI runners, harvested secrets from process memory and metadata services, and encrypted loot before exfiltration.
  • Some failed exfiltration attempts reportedly led the malware to create public repositories in victims’ GitHub accounts to upload stolen data.
  • CloudSEK recommends rapid credential rotation, log review, and validation of exposure for organizations matched with high confidence.

MITRE Techniques

  • [T1068] Exploitation for Privilege Escalation – The stealer escalated to root on compromised CI runners before collecting credentials (‘escalated to root’).
  • [T1552.001] Credentials in Files – The actor harvested secrets from environment files and CI/CD secrets stored on disk (‘env files and CI/CD secrets’).
  • [T1552.004] Private Keys – SSH keys and other private keys were collected from the affected systems (‘SSH keys’).
  • [T1552.005] Cloud Instance Metadata API – Cloud credentials were read from the instance metadata service without needing an exploit (‘read straight from the instance metadata service (IMDS)’).
  • [T1555] Credentials from Password Stores – The malware scraped secrets from process memory, including masked GitHub Actions values (‘scraped directly from /proc//mem’).
  • [T1136.003] Create Account: Cloud Account – The malware created a public repository inside the victim’s GitHub account to stage stolen data (‘created a public repository inside the victim’s own GitHub account’).
  • [T1027] Obfuscated Files or Information – The collected data was encrypted with AES-256 and protected by a hard-coded RSA-4096 key to prevent inspection (‘sealed with AES-256 under a hard-coded RSA-4096 key’).
  • [T1105] Ingress Tool Transfer – The poisoned packages were published to PyPI and distributed downstream into build environments (‘published the malicious 1.82.7 and 1.82.8 releases to PyPI’).
  • [T1195.002] Supply Chain Compromise: Compromise Software Supply Chain – Trusted tooling was compromised to inject malicious code into LiteLLM releases (‘one un-revoked token, three tools deep’).
  • [T1059.006] Command and Scripting Interpreter: Python – A malicious .pth file executed when Python started, enabling automatic code execution (‘a malicious .pth file runs when Python starts’).
  • [T1074.001] Local Data Staging – The actor staged stolen data for exfiltration before shipping it to a typosquatted domain or public repository (‘The loot was encrypted and shipped’).
  • [T1567.002] Exfiltration to Cloud Storage – Stolen data was uploaded as a release asset in a GitHub repository when direct exfiltration failed (‘uploaded the stolen data there as a release asset’).

Indicators of Compromise

  • [Domains] Exposure and exfiltration infrastructure – exposure.cloudsek.com, typosquatted domain (not named in article)
  • [Package names / versions] Malicious releases and affected software – LiteLLM 1.82.7, LiteLLM 1.82.8, Trivy, Checkmarx KICS
  • [Repository names] Suspicious GitHub repository activity – tpcp-docs/docs-tpcp, public repository inside the victim’s GitHub account
  • [Advisory / reference IDs] Public tracking and response references – FLASH-20260702-01, FBI FLASH-20260702-01
  • [File / script types] Malicious startup payloads and build artifacts – .pth file, env files, release asset
  • [Crypto / key material] Protection used on stolen data – AES-256, RSA-4096


Read more: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines