LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD Environments
Brief
A major software supply chain breach involving LiteLLM has reportedly exposed credentials, cloud keys, API tokens, and internal configuration data from thousands of enterprise CI/CD environments.
Forensic investigations by Snyk, Trend Micro , and Cycode show that LiteLLM was not the initial target.
The attack reportedly began when threat actor TeamPCP compromised the GitHub Actions pipeline associated with Trivy, a widely used open-source vulnerability scanner.
LiteLLM developers used Trivy in their own CI/CD workflow. This gave the compromised scanner legitimate access to the LiteLLM runner environment.
Attackers allegedly used that access to steal PyPI publishing tokens, then used the tokens to release malicious LiteLLM package versions 1.
- 7 and 1.
- 8.
The malicious releases used a Python . pth startup hook.
