CSIDB logo
Incident

Amazon Web Services

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 00:24

Linked entities

Victim
Amazon Web Services
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending

Summary

A supply chain compromise of the open‑source vulnerability scanner Trivy allowed attackers to inject a malicious version into the LiteLLM build pipeline, which was then published as compromised releases to the Python Package Index. The tainted LiteLLM instances harvested credentials from thousands of corporate CI/CD environments, exposing over 150 GB of data that included AWS secret keys, Salesforce client secrets, Slack signing tokens, Azure variables and AI provider API keys linked to organizations such as Samsung, Cisco and many others. Analysis of the stolen archive revealed hundreds of thousands of files containing cloud IAM keys, database passwords and third‑party tokens, with many lacking clear ownership markers, indicating potential unknown exposure across numerous enterprises.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 19 2026 the cybercriminal group TeamPCP used stolen credentials to publish a compromised version of the open‑source vulnerability scanner Trivy to the Python Package Index. The compromised Trivy was automatically pulled into the build pipeline of the LiteLLM AI proxy gateway, granting the malicious scanner read access to the runner environment. Within that environment the attackers exfiltrated LiteLLM’s PyPI publishing tokens. Using those tokens, TeamPCP uploaded two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, to PyPI on March 24 2026. The malicious packages were subsequently downloaded and executed in countless continuous‑integration and continuous‑deployment pipelines, allowing the harvest of secrets from the runner environments. Hudson Rock later obtained and analyzed a 153 GB archive containing 433 909 files that had been stolen during the attack. The archive included 118 829 CI runner dumps that Hudson Rock attributed to 2 488 corporate domains.

The dataset exposed a wide range of sensitive material, including AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys. Hudson Rock identified information linked to organizations such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deer, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte, and Siemens. CloudSEK, working from a separate set of about 434 000 stolen files, estimated that the exposure reached close to 2 500 organizations. Many of the dumped files lacked clear ownership markers, containing database passwords, third‑party API keys, and cloud credentials without associated company emails, custom domains, or internal server names, which means some organizations may have been unaware that their credentials were present in the leak.

In response, Hudson Rock urged organizations that use AI proxy infrastructure, third‑party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for the compromised LiteLLM versions and to treat any secrets accessible to the LiteLLM environment as compromised. Some organizations reported rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity dating back to March 24, and checking for unauthorized .pth files and suspicious systemd services. Security researcher Kevin Beaumont confirmed the legitimacy of the data by attempting to use credentials from the archive and finding that many of them were still valid. Hudson Rock noted that accurate attribution depends on hard infrastructure markers rather than simple committer emails, and that the scale of the breach required a new level of response from the cybersecurity community.

Sources

Sources available to members: 1 source.

CSIDB