CloudSEK finished attributing the stolen data from March 2026 LiteLLM supply chain attack: 118,829 CI runner memory dumps traced to 2,488 corporate domains across roughly 434,000 CI/CD pipelines, including Nvidia, AWS, Samsung, FedEx and Volkswagen. The malicious LiteLLM packages were live on PyPI for only 40 minutes.

Read the full story: LiteLLM breach: 40 minutes, 2,488 companies exposed →

Transcript

One unrevoked token just exposed secrets from twenty-four hundred companies, including Nvidia, Samsung, FedEx and Volkswagen. Here is how. Nobody attacked LiteLLM. They attacked Trivy, the vulnerability scanner LiteLLM ran automatically in its build pipeline. A poisoned Trivy release leaked LiteLLM's publishing credentials, and two malicious versions went out to PyPI. Those packages were live for forty minutes. That was enough to reach an estimated four hundred and thirty-four thousand CI pipelines, because nothing in a modern build waits. Every pipeline that installed it ran the payload before a single line of application code. Out came cloud keys, SSH keys, registry tokens, and AI provider keys with real spending attached. A scanner would not have caught it, because the scanner was the attack. If LiteLLM was in your tree in March, rotate everything that process could read.