Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises – Claim Your Ethical Disclosure
TeamPCP orchestrated a multi-ecosystem supply chain attack that began by compromising Trivy’s GitHub Actions pipeline and ended with malicious LiteLLM packages silently stealing secrets from CI/CD environments worldwide. The leak exposed 153GB of data from 118,829 pipeline runs tied to 2,488 domains, affecting organizations including AWS, Samsung, Cisco, Salesforce, ServiceNow, Siemens, and others. #TeamPCP #Trivy #LiteLLM #HudsonRock #Cavalier #Orange #Boeing #Roku #AdsWizz

Keypoints

  • TeamPCP compromised Trivy’s GitHub Actions pipeline to seed the broader supply chain attack.
  • The attackers used LiteLLM versions 1.82.7 and 1.82.8 to exfiltrate CI/CD secrets and credentials.
  • A .pth Python startup hook enabled stealthy execution, persistence, and lateral movement.
  • The exposed dataset contained 153GB of raw dumps from 118,829 pipeline runs across 2,488 domains.
  • Impact was confirmed across major organizations, including AWS, Samsung, Cisco, Salesforce, and AdsWizz.

Read More: https://www.infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure/