LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
• A supply chain attack by TeamPCP poisoned LiteLLM’s build pipeline via Trivy, potentially exposing 2,500 companies and 434,000 CI/CD pipelines. • The malicious payload targeted CI/CD runners to steal SSH keys, cloud credentials, Kubernetes tokens, and environment secrets from process memory. • The attack specifically sought LLM API keys and gateway settings, creating a direct path to sensitive data and connected AI systems.
cybersecuritynews.com