LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
Brief
The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more.
Resecurity (USA) estimated the most affected sectors by the “ SANDCLOCK ” backdoor , which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences.
By compromising a well-known component in AI applications, adversaries will multiply the blast radius—some of the victim organizations are still unaware of the backdoor and its impact. LiteLLM is a popular open-soure AI gateway and utility library that unifies API calls for over 100 large language model providers, such as OpenAI, Anthropic, Google Gemini, and local Ollama models .
Such incidents involve substantial MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond).
