This page may contain stale information. Last updated: 2026-08-14
Overview
Security risk class where widely shared AI gateway/proxy packages (e.g., litellm) become single points of failure for thousands of CI/CD environments, amplifying short package-registry exposures into months-long credential crises.
Timeline
- 2026-03: teampcp LiteLLM PyPI compromise (~40 minutes)
- 2026-07: FBI FLASH on long-lived credential weaponization
- 2026-08-12/14: hudson-rock archive + kevin-beaumont still-live tests (2026-08-14-litellm-credentials-still-live)
Contradiction
Prefer hudson-rock 153 GB / 2,488 domains figures over conflicting secondary archive-size wording (see litellm).
Key Players
Analysis
The operational lesson is secret-rotation-failure: damage window runs until every pipeline secret is rotated and verified, not until PyPI quarantine. Persistence via .pth and systemd backdoors extends beyond key rotation alone.