Cyber Incident Victim: AdsWizz
Timeline
Summary
A supply chain compromise of the open‑source vulnerability scanner Trivy allowed attackers to inject a malicious version into the LiteLLM build pipeline, which then published poisoned releases 1.82.7 and 1.82.8 to PyPI. The compromised pipeline harvested credentials from thousands of CI/CD environments, yielding a 153GB archive containing over 430,000 files and 118,000 CI runner dumps linked to nearly 2,500 corporate domains, including AWS, Samsung, Cisco, Salesforce and others. Infrastructure markers in one dump pointed to a self‑hosted GitLab instance at gitlab.adswizz.com, identifying the exposed data as belonging to AdsWizz, a SiriusXM subsidiary. The leaked material included AWS secret keys, Salesforce client secrets, Slack signing secrets, Azure variables and AI provider API keys, demonstrating the broad reach of the attack.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The incident began with the compromise of the open‑source vulnerability scanner Trivy in March 2026, when the cybercriminal group TeamPCP used stolen credentials to publish a poisoned version of the tool. LiteLLM’s automated build pipeline installed this compromised Trivy, granting the malicious scanner read access to the runner environment and allowing the attackers to exfiltrate the project’s PyPI publishing tokens. With those tokens, TeamPCP uploaded two malicious releases of LiteLLM—versions 1.82.7 and 1.82.8—to the Python Package Index on 24 March 2026. The window of exposure lasted roughly 40 minutes, during which the compromised LiteLLM dependency was installed in over 430 000 instances, leading to the harvesting of millions of secrets. Hudson Rock later obtained and analyzed a 153 GB archive containing 433 909 files, attributing 118 829 CI runner dumps to 2 488 corporate domains. The dataset included AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, AI provider API keys, database passwords, third‑party API keys and cloud credentials, and was linked to organizations such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deer, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte and Siemens. CloudSEK, working from a similar set of about 434 000 stolen files, estimated that close to 2 500 organizations were exposed.

In the same archive, a leaked pipeline was tied to a committer email at SiriusXM, but infrastructure markers within the dump—specifically a self‑hosted GitLab instance at gitlab.adswizz.com—pointed to AdsWizz, a subsidiary of SiriusXM. Hudson Rock emphasized that correct attribution relied on these hard infrastructure markers rather than on committer emails alone, thereby linking the exposed data to AdsWizz’s GitLab environment. The archive also contained a large share of files with no obvious owner, including credentials lacking corporate email addresses, custom domains or internal server names, which meant that some organizations could have exposed secrets without being aware of the exposure. Despite the scale of the breach, some affected organizations treated the incident with low urgency; one organization reported having rotated all credentials only to find that nearly all of them still functioned when tested. Security researcher Kevin Beaumont confirmed the legitimacy of the data, noting that multiple victim organizations had validated its contents. Hudson Rock observed that accurately identifying victims required looking beyond surface‑level indicators to examine the actual infrastructure boundaries reflected in the stolen material.
