Largest AI Supply Chain Breach of 2026: LiteLLM

Published: August 12, 2026 — Hudson Rock

Primary threat-intel analysis:

  • Threat actor: TeamPCP
  • Chain: Trivy GitHub Actions poison → LiteLLM PyPI tokens → malicious 1.82.7 / 1.82.8
  • Payload: .pth startup hook; env harvest; kube/aws creds; K8s lateral movement; systemd persistence
  • Archive: 153 GB RAR, 433,909 files; 118,829 CI dumps → 2,488 corporate domains
  • Not widely leaked yet — rotation window still open
  • Remediation: audit 1.82.7/1.82.8; aggressive credential revocation; check .pth and systemd backdoors
  • Ethical disclosure portal for domain lookup