Threats & Adversaries · Supply Chain

LiteLLM Breach Grew Into CI Secret Spill

Hudson Rock says it has analyzed a 153GB archive from the LiteLLM supply-chain attack, tying 433,909 files and 118,829 CI runner dumps to 2,488 corporate domains, with valid March credentials in the haul. The original compromise still matters: TeamPCP poisoned Trivy, LiteLLM’s build pipeline trusted it, and the attackers used that access to steal PyPI publishing tokens and ship malicious LiteLLM releases 1.82.7 and 1.82.8 on March 24.

The important part is what the runner could see. Because the malicious step executed inside CI/CD, it could read whatever secrets the build environment exposed, so the dump contains reusable logins and API keys, not just one compromised package account. That makes the breach wider than LiteLLM itself.

If your runners can reach cloud keys, Slack signing secrets, or AI/API tokens, this is a corporate secret-exposure event with downstream access paths that may outlive the package cleanup. The blast radius sits with the build systems and services those runners could touch, not only with the named open-source project.

3 sources · Aug 14

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-08-15

Every edition of this story: LiteLLM Breach Grew Into CI Secret Spill

More from today