Threat actor TeamPCP exploited a vulnerability in Aqua Security's Trivy scanner to compromise the LiteLLM Python library and proxy server. LiteLLM's continuous integration pipeline automatically installed the malicious Trivy version, which injected code into LiteLLM versions 1.82.7 and 1.82.8. The compromised packages were pushed to the Python Package Index. The malicious releases remained active for 40 minutes, according to scworld.com.
That 40-minute window was sufficient for the injected code to propagate through automated build systems. TeamPCP did not target LiteLLM directly but achieved compromise indirectly through the scanner dependency. The attack demonstrates a lateral dependency chain where compromising a security tool provides a vector into a downstream AI development library. The injected code harvested secrets from the CI environments that installed the compromised LiteLLM releases.
The attack was first disclosed in March 2026 and detailed in subsequent analyses by security firms CloudSEK and Hudson Rock. The indirect compromise vector means the vulnerability existed in the Trivy scanner itself, which LiteLLM trusted as a dependency in its build process. The open question is whether Aqua Security has patched the underlying Trivy vulnerability that enabled the injection. The evidence does not state the specific mechanism used to exploit Trivy.
CloudSEK estimates the attack impacted over 2,500 organizations and more than 434,000 CI/CD pipelines, as reported by news.ssbcrack.com. Hudson Rock obtained a 153GB RAR archive containing 433,909 files associated with the TeamPCP campaign. Analysis of the archive attributed 118,829 CI runner dumps to 2,488 corporate domains. The dumps contained environment variables, cloud credentials, API tokens, configuration files, and other secrets.
The discrepancy between 2,500 organizations and 2,488 corporate domains suggests Hudson Rock's count reflects verified domains while CloudSEK's figure may include additional affected entities. The 434,000 pipeline figure from CloudSEK and the 433,909 file count from Hudson Rock align closely, indicating both firms analyzed overlapping datasets. The scale implies that a single compromised dependency in a widely used AI tool can cascade across hundreds of thousands of build environments within minutes.
Affected entities include Microsoft, Amazon, Cisco, Samsung, and Salesforce, according to arstechnica.com. The presence of major technology, industrial, financial, and telecommunications firms in the dump indicates LiteLLM has penetrated enterprise AI development workflows. The broad exposure could enable account takeovers, data theft, and further attacks. The total volume of leaked credentials reached 195TB, as stated in the headline findings.
CloudSEK identified cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys in the exfiltrated data. The presence of AI provider keys specifically indicates the attack targeted secrets used to access large language model APIs, which is the core function of LiteLLM as a proxy server. The diversity of credential types means attackers could potentially pivot from CI environments into cloud infrastructure, source code repositories, and package registries.
Hudson Rock's analysis of the 153GB archive linked the compromised credentials to 2,488 corporate domains across technology, industrial, financial, and telecommunications sectors. The CI runner dumps contained configuration files alongside secrets, providing attackers with contextual information about the environments they could access. That suggests the attack payload was designed to harvest both authentication material and infrastructure topology data, increasing the potential for lateral movement within affected organizations.
The combination of package publishing credentials and repository tokens in the dump indicates attackers could theoretically push malicious code to downstream dependencies. The presence of Kubernetes secrets expands the attack surface from application layers to container orchestration platforms. The evidence does not state whether any of the exposed credentials have been actively exploited in subsequent attacks. The total dataset of 195TB represents one of the largest credential exposures linked to a single supply chain compromise.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.