A supply-chain attack that compromised LiteLLM's build pipeline affected more than 2,500 companies and roughly 434,000 CI/CD pipelines, according to CloudSEK. The threat group TeamPCP compromised Aqua Security's Trivy scanner and its GitHub Actions in March, which infected LiteLLM's CI pipeline and led to two malicious packages (versions 1.82.7 and 1.82.8) being published to PyPI for about 40 minutes. Malware including CanisterWorm, SandClock, Mini Shai-Hulud, and Miasma harvested cloud credentials, API keys, Kubernetes tokens, and crypto wallet data, exfiltrating them to a typosquatted domain or uploading them to victims' own public GitHub repos. Victims include Nvidia, Intel, Zscaler, AWS, Cisco, Salesforce, ServiceNow, John Deere, Airbus, FedEx, Volkswagen, Bayer, and Deloitte. The FBI separately issued an advisory noting the same threat actors also compromised Checkmarx's KICS and the Telnyx Python SDK, warning organizations to treat stolen credentials as a persistent risk.

5m read timeFrom devops.com
Post cover image
Table of contents
Only 40 Minutes Were NeededWidespread CompromiseStealing Credentials, API Keys, and Other InfoHigh-Profile VictimsTargeting AI Infrastructure

Questions this post answers

How did the LiteLLM supply chain attack happen and what was compromised?

Threat group TeamPCP first compromised Aqua Security's Trivy open source vulnerability scanner and its GitHub Actions in March, which then infected LiteLLM's CI pipeline. This led to malicious code being published in LiteLLM releases 1.82.7 and 1.82.8 on PyPI, where the packages stayed live for about 40 minutes before removal but had already spread widely. Track fast-moving supply chain incidents like the LiteLLM breach as they unfold on daily.dev.

How many organizations were affected by the LiteLLM and Trivy supply chain attack?

More than 2,500 companies and roughly 434,000 CI/CD pipelines were exposed, per CloudSEK's threat intelligence unit. Victims include Nvidia, Intel, Zscaler, AWS, Cisco Systems, Salesforce, ServiceNow, John Deere, Airbus U.S., FedEx, Volkswagen, Bayer, and Deloitte. Exposure does not necessarily mean each organization was fully compromised. Security teams assessing their own exposure follow breach scope updates on daily.dev.

What malware was used to steal credentials in the TeamPCP LiteLLM attack?

TeamPCP deployed CanisterWorm to harvest cloud access tokens, credentials, and API keys for AWS, GCP, and Azure, plus SandClock to target AWS credentials, Kubernetes service account tokens, and crypto wallet data. Self-replicating worms Mini Shai-Hulud and Miasma also spread across npm and PyPI stealing credentials and damaging configs, with stolen data sometimes uploaded to victims' own public GitHub repos. Developers hardening CI/CD pipelines against credential theft follow malware breakdowns like this on daily.dev.

4.7K Impressions