Cyber Incident Victim: SiriusXM
Timeline
Summary
A supply chain compromise of the open‑source LiteLLM proxy gateway led to the publication of malicious versions that harvested credentials from thousands of corporate CI/CD pipelines, exposing a 153 GB archive containing secrets such as cloud keys, API tokens, and source‑code artifacts. Analysis of the archive by Hudson Rock linked a leaked pipeline to a committer email associated with SiriusXM, while infrastructure markers pointed to its subsidiary AdsWizz, indicating that the subsidiary’s environment was among the affected organizations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On March 19 2026 the cybercriminal group TeamPCP used stolen credentials to publish a compromised version of the open‑source vulnerability scanner Trivy. Because LiteLLM’s build pipeline automatically installed Trivy, the poisoned scanner gained read access to the runner environment and allowed the attackers to steal LiteLLM’s PyPI publishing tokens. With those tokens TeamPCP released two malicious versions of LiteLLM, numbered 1.82.7 and 1.82.8, to the Python Package Index on March 24 2026. The malicious releases harvested secrets from CI/CD pipelines during execution, and the collected data was later assembled into a 153 GB archive containing 433 909 files. Hudson Rock obtained and analyzed the archive, attributing 118 829 CI runner dumps to 2 488 corporate domains and identifying exposed credentials such as AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables and AI provider API keys.

Among the data Hudson Rock noted a leaked pipeline that was tied to a committer email at SiriusXM, but infrastructure markers in the same dump—including a self‑hosted GitLab instance at gitlab.adswizz.com—pointed to AdsWizz, a subsidiary of SiriusXM. Hudson Rock emphasized that correct identification of the affected organization relies on hard infrastructure markers rather than on committer emails alone. A large share of the dumped files lacked obvious ownership, containing database passwords, third‑party API keys and cloud credentials without a company email address, custom domain or internal server name that could identify the source organization. This means some entities may have had exposed credentials in the dataset without being aware of the exposure.
Despite the scale of the breach, some organizations appeared to treat the exposure with less urgency than the findings warranted. One impacted organization told security researcher Kevin Beaumont that it had rotated all credentials and considered the issue a nothingburger; Beaumont tested the credentials and found that almost all of them still worked. Hudson Rock observed that the data was not leaked elsewhere at the moment and was not circulating widely, noting that this situation created a window before any potential wider dissemination. The archive also included references to numerous other companies such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte and Siemens.
