Terabytes of Cloud Credentials Exfiltrated From 2,500 Organizations via Poisoned LiteLLM PyPI Packages — 434,000 CI/CD Pipelines Exposed
CloudSEK disclosed that Team PCP compromised LiteLLM PyPI versions 1.82.7 and 1.82.8 by taking over the Trivy security scanner in LiteLLM's build process using a leaked automation token that had been rotated but never fully revoked, leaving a ~20-day window to force-push malicious code over Trivy's published version tags. Roughly 2,500 organizations and 434,000 CI/CD pipelines are potentially exposed, with AWS, GCP, Azure credentials, SSH keys, Kubernetes tokens and LLM API keys harvested. Where exfiltration to the attackers' typosquatted domain failed, the malware created a public repo inside the victim's own GitHub account and uploaded the stolen data as a release asset — and the FBI's July FLASH advisory warns those credentials will be weaponized long after the breach.
↳ Follow the thread