LiteLLM infected 2,500 companies

Did you know that a single unrevoked token can compromise thousands of organizations at once?
A supply chain attack affected more than 2,500 companies in a matter of minutes.
LiteLLM was not the real target. Attackers first compromised Trivy, Aqua Security’s scanner, and from there the malware traveled to LiteLLM automatically.
LiteLLM’s pipeline installed the tainted version of Trivy without anyone noticing, and two poisoned versions reached PyPI before anyone reacted.

Just forty minutes were enough to unleash all the chaos.
LiteLLM versions 1.82.7 and 1.82.8 were available on PyPI for just forty minutes. More than enough time. The malicious payload executed on every Python invocation, with no explicit import required, meaning any system with the package installed was immediately and silently exposed, leaving no obvious indication that something was wrong.
434,000 CI/CD pipelines touched in that time.
According to CloudSEK’s analysis, the spread was so rapid because automated build systems compress response time: scheduled tasks, dependency resolvers, ephemeral runners, and cached layers copied the malicious artifact at a speed that completely outpaced the detection and credential rotation window, even after the packages were removed from the repository.
Nvidia, AWS, Samsung, and Cisco are on the list of exposed organizations.
CloudSEK notes that the exposure data are reconstructed estimates: not all listed organizations suffered a confirmed compromise, nor were all credentials stolen. Even so, the scale of the potential risk is enormous. Among the names that also appear are Salesforce, Siemens, FedEx, Volkswagen, Zscaler, and the London Stock Exchange Group, among many others.

A single unrevoked token started it all.
The entry vector was a publishing token that was never invalidated after the previous attack on Trivy. That oversight connected three distinct tools in a single chain of compromise and turned a one-off credential leak into an ecosystem-scale exposure.
What was exposed goes far beyond the obvious.
The attack did not only compromise code. Among the potentially accessible data are package publishing credentials, cloud keys, SSH keys, session tokens, environment variables, and AI provider keys. With that arsenal, an attacker can take control of accounts, steal data, inject malicious commits, or deploy additional malware without triggering immediate alerts.
Any secret accessible to LiteLLM must be considered compromised right now.
CloudSEK is explicit: that includes secrets in process memory, injected into the job, stored on disk, or retrievable through an instance metadata service. Credential rotation must be accompanied by a thorough log review to determine the true scope.

The next major attack will target AI infrastructure directly.
CloudSEK warns that AI systems have become high-value nodes where data, identity, and compute capacity converge. Compromising an AI control layer means gaining access to everything connected to it.
AI connects everything else.
This incident demonstrated that a supply chain attack on an AI product is not just a software breach: it is a lever for compromising adjacent identities and systems. As AI becomes more deeply integrated into corporate environments, its appeal as a primary entry vector grows.
Review, rotate, and audit without delay.
If your organization uses or has used LiteLLM, the time to act is now. Do not wait to confirm the compromise: rotate first, then audit.
What to do now
- ✓Revoke and rotate all credentials accessible to LiteLLM immediately.
- ✓Audit your CI/CD pipeline logs to detect anomalous activity.
- ✓Verify which versions of LiteLLM you installed and exactly when.
Does your team have a clear protocol for rotating credentials in the event of a supply chain attack?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.
Information meant to help you act and protect yourself before the problem reaches you.
RATING
8
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




