Largest AI Supply Chain Breach of 2026: LiteLLM
Published: August 12, 2026 — Hudson Rock
Primary threat-intel analysis:
- Threat actor: TeamPCP
- Chain: Trivy GitHub Actions poison → LiteLLM PyPI tokens → malicious 1.82.7 / 1.82.8
- Payload: .pth startup hook; env harvest; kube/aws creds; K8s lateral movement; systemd persistence
- Archive: 153 GB RAR, 433,909 files; 118,829 CI dumps → 2,488 corporate domains
- Not widely leaked yet — rotation window still open
- Remediation: audit 1.82.7/1.82.8; aggressive credential revocation; check .pth and systemd backdoors
- Ethical disclosure portal for domain lookup