CVE-2026-33634
Known exploited · CISA KEV
CISA federal remediation date Apr 9 · date passed
Threats · 45 days ago
Hudson Rock says it has analyzed a 153GB archive from the LiteLLM supply-chain attack, tying 433,909 files and 118,829 CI runner dumps to 2,488 corporate domains, with valid March credentials in the haul. The original compromise still matters: TeamPCP poisoned Trivy, LiteLLM’s build pipeline trusted it, and the attackers used that access to steal PyPI publishing tokens and ship malicious LiteLLM releases 1.82.7 and 1.82.8 on March 24.
The important part is what the runner could see. Because the malicious step executed inside CI/CD, it could read whatever secrets the build environment exposed, so the dump contains reusable logins and API keys, not just one compromised package account. That makes the breach wider than LiteLLM itself.
If your runners can reach cloud keys, Slack signing secrets, or AI/API tokens, this is a corporate secret-exposure event with downstream access paths that may outlive the package cleanup. The blast radius sits with the build systems and services those runners could touch, not only with the named open-source project.
Known exploited · CISA KEV
CISA federal remediation date Apr 9 · date passed
3 sources covering this story
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security
Stolen credentials tied to the LiteLLM breach have surfaced in a 153GB archive linked to thousands of corporate domains.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ organizations.
Part of the PlainSec briefing for 2026-08-15