← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 17, 2026 · 17:09via Security Affairs

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

Brief

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more.

Resecurity (USA) estimated the most affected sectors by the “ SANDCLOCK ” backdoor , which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences.

By compromising a well-known component in AI applications, adversaries will multiply the blast radius—some of the victim organizations are still unaware of the backdoor and its impact. LiteLLM is a popular open-soure AI gateway and utility library that unifies API calls for over 100 large language model providers, such as OpenAI, Anthropic, Google Gemini, and local Ollama models .

Such incidents involve substantial MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond).

Read more on Security Affairs