40 Minute LiteLLM Hack Exposes Cloud Keys and CI/CD Secrets From 2,488 Companies
Brief
A supply-chain breach involving LiteLLM has widened from a compromised software release into an exposure event affecting thousands of corporate build environments.
The incident shows how one poisoned dependency can reach far beyond its original project, placing cloud access and deployment credentials within reach of attackers.
The attack path reportedly started with a compromise of the Trivy scanning tool used in LiteLLM’s build process.
Malicious code was then able to run in automated CI/CD environments, where it searched for credentials that developers and services need to build, test and deploy software.
HudsonRock analysts identified a 153GB archive linked to the campaign, containing 433,909 files and 118,829 CI runner dumps tied to 2,488 corporate domains.
