- Over 2,500 organizations—including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group—had login credentials stolen during a supply-chain compromise targeting LiteLLM
- The breach originated from a manipulated version of Aqua Security’s Trivy scanner, which LiteLLM unknowingly integrated into its operations
- Compromised credentials remain functional months later, posing an ongoing security threat
Cloud security firms CloudSEK and Hudson Rock confirmed that more than 2,500 entities were affected by the attack. The exploit leveraged a vulnerability in Trivy, an open-source security tool, allowing attackers to deploy a credential-stealing payload.
While LiteLLM itself remained unaltered, its automated dependency on Trivy created an entry point for TeamPCP—a financially motivated hacking group. The stolen data included cloud API keys, SSH credentials, Kubernetes tokens, and AI service credentials.
The scale of the breach is unprecedented, with Hudson Rock reporting a 153 GB archive of exfiltrated data from a 195 TB file. Both firms are monitoring domain registrations to help victims identify compromised systems.
Independent tests by researcher Kevin Beaumont revealed that some stolen credentials remained active despite supposed rotations, underscoring the attack’s persistence.
Also Read
- Innovative Scientific Solutions: How Phages, Smart Packaging, and Edible Coatings Are Combating Global Food Waste
- Trump Announces a New Policy for a ‘Golden Age of Space Transportation’
- Google Pixel 11 Review: Incremental Improvements in Design and Performance
- Trump Administration Escalates Assault on California Climate Policies


