LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
Brief
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident placed build systems, cloud accounts and source code at risk, although the malicious releases were available for only about 40 minutes.
The campaign began after attackers compromised the release process for the Trivy scanner. LiteLLM’s build pipeline installed that tool without locking it to a verified version, allowing poisoned code to enter the build and produce malicious LiteLLM packages on PyPI.
CloudSEK analysts identified the activity as part of a campaign attributed to TeamPCP. Its reconstructed dataset linked more than 2,500 organizations and 434,000 CI/CD pipeline runs to the affected path, but exposure does not prove every organization was breached.
