Menu
Browse

Cyber Incident Victim: Amazon Web Services

Date

Mar 2026

Location

United States of America

Status

Unknown

Updated

2026-08-17 20:19

Timeline
Occurred
Mar 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

A supply chain compromise of the open‑source vulnerability scanner Trivy allowed attackers to inject a malicious version into the LiteLLM build pipeline, which was then published as compromised releases to the Python Package Index. The tainted LiteLLM instances harvested credentials from thousands of corporate CI/CD environments, exposing over 150 GB of data that included AWS secret keys, Salesforce client secrets, Slack signing tokens, Azure variables and AI provider API keys linked to organizations such as Samsung, Cisco and many others. Analysis of the stolen archive revealed hundreds of thousands of files containing cloud IAM keys, database passwords and third‑party tokens, with many lacking clear ownership markers, indicating potential unknown exposure across numerous enterprises.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On March 19 2026 the cybercriminal group TeamPCP used stolen credentials to publish a compromised version of the open‑source vulnerability scanner Trivy to the Python Package Index. The compromised Trivy was automatically pulled into the build pipeline of the LiteLLM AI proxy gateway, granting the malicious scanner read access to the runner environment. Within that environment the attackers exfiltrated LiteLLM’s PyPI publishing tokens. Using those tokens, TeamPCP uploaded two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, to PyPI on March 24 2026. The malicious packages were subsequently downloaded and executed in countless continuous‑integration and continuous‑deployment pipelines, allowing the harvest of secrets from the runner environments. Hudson Rock later obtained and analyzed a 153 GB archive containing 433 909 files that had been stolen during the attack. The archive included 118 829 CI runner dumps that Hudson Rock attributed to 2 488 corporate domains.

Cyber Incident Image

The dataset exposed a wide range of sensitive material, including AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys. Hudson Rock identified information linked to organizations such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deer, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte, and Siemens. CloudSEK, working from a separate set of about 434 000 stolen files, estimated that the exposure reached close to 2 500 organizations. Many of the dumped files lacked clear ownership markers, containing database passwords, third‑party API keys, and cloud credentials without associated company emails, custom domains, or internal server names, which means some organizations may have been unaware that their credentials were present in the leak.

In response, Hudson Rock urged organizations that use AI proxy infrastructure, third‑party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for the compromised LiteLLM versions and to treat any secrets accessible to the LiteLLM environment as compromised. Some organizations reported rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity dating back to March 24, and checking for unauthorized .pth files and suspicious systemd services. Security researcher Kevin Beaumont confirmed the legitimacy of the data by attempting to use credentials from the archive and finding that many of them were still valid. Hudson Rock noted that accurate attribution depends on hard infrastructure markers rather than simple committer emails, and that the scale of the breach required a new level of response from the cybersecurity community.

Sources
Sources available to members
1 source