Explore the latest developments concerning Over 2,500 Organizations.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
More than 2,500 organizations and over 430,000 CI/CD pipelines were affected by the LiteLLM supply chain attack earlier this year, CloudSEK reports.
The LiteLLM compromise was disclosed shortly after the supply chain attack on Aqua Security’s Trivy open source vulnerability scanner and was a direct result of it.
According to CloudSEK, TeamPCP, the threat actor behind multiple high-profile open source software (OSS) compromises, never targeted LiteLLM directly.
The open source Python library and proxy server was compromised after its CI pipeline installed the compromised Trivy version automatically. Two LiteLLM versions, namely 1.82.7 and 1.82.8, were pushed to PyPI, providing the hackers with access to all the information LiteLLM touched.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.
Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more than 2,500 organizations.
Those totals are not a victim count. CloudSEK told The Hacker News the material came from confidential intelligence sources and consists of captured loot and log files it assessed as belonging to the campaign, not data gathered from the organizations it names. The files were taken, in other words.
7000A Car Jump Starter with Air Compressor Battery Booster 12V Power Bank with LED Flashlight, Smart Cable with Voltage Display
CloudSEK Links March LiteLLM Supply Chain Breach to 2,500 Organizations
Threat-intelligence firm CloudSEK said in a report published August 11, 2026 that it has identified more than 2,500 organizations potentially exposed by the March 2026 supply-chain compromise of LiteLLM, the open-source gateway developers use to route requests across AI models, and reconstructed roughly 434,000 CI/CD pipelines touched by the exposure.
The figures come from a CloudSEK research report built on a victim dataset the company says its threat-intelligence team obtained covering the March campaign. CloudSEK’s dataset carries high-confidence matches tied to corporate domains, repositories, credentials, or infrastructure belonging to organizations including NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales, and London Stock Exchange Group. The firm is explicit about what the matches mean: high confidence describes the strength of evidence linking exposed information to an organization, not proof that the organization was breached or that an attacker used what was taken.
For more detailed information, explore updates concerning Over 2,500 Organizations.



















