TeamPCP利用咗一個連鎖式嘅供應鏈攻擊:佢哋先毒化 Trivy(一個開源安全掃描器),然後LiteLLM嘅CI/CD管道——因為喺建構安全掃描入面用咗已被入侵嘅Trivy依賴——喺建構過程中受感染,令攻擊者取得LiteLLM嘅PyPI發布憑證 。呢啲憑證讓TeamPCP可以直接將毒包推上PyPI,繞過LiteLLM正常嘅GitHub發布流程
。有分析指出,攻擊「源於LiteLLM嘅CI/CD安全掃描工作流程所用嘅Trivy依賴」
。
外洩嘅域名涵蓋科技、金融、工業同電信等領域嘅大型企業。多個來源確認嘅組織包括 Amazon (AWS)、Samsung、Cisco、Microsoft、NVIDIA、Salesforce、Volkswagen、FedEx、Deloitte、ServiceNow、S&P Global、Siemens 同 BT Group 。Hudson Rock指出,即使事發幾個月後,呢批存檔入面嘅憑證「仍然有效」
。
Ars Technica報道呢次入侵之後,Kevin Beaumont 獨立測試咗一間聲稱「已經全面更換憑證」嘅大型美國科技公司。佢用負責任披露方式測試之後發現,「幾乎全部憑證都用得」——即係話呢間公司並冇真正更換已被外洩嘅機密,同佢哋公開講嘅唔一樣 。
所有曾經喺LiteLLM 1.82.7或1.82.8入面出現過嘅機密資料——包括API金鑰、雲端憑證、SSH金鑰、Kubernetes配置同其他敏感數據——都必須視為完全外洩。 即時更換2026年3月24日窗口期內可能暴露嘅每一項憑證係必不可少嘅,唔好理間公司話已經做咗更換 。呢次攻擊被視為2026年最大嘅AI基礎設施供應鏈入侵,被盜嘅數據對後續攻擊構成持續威脅,Beaumont嘅測試正好證實咗呢一點
。
LiteLLM Security Townhall Updates
LiteLLM Security Update: Suspected Supply Chain Incident
HelpNetSecurity: 153GB of stolen credentials surface after LiteLLM supply chain attack
The CyberSec Guru: 2,500+ Organizations Exposed in LiteLLM Supply Chain Attack
B2BNN: A Trusted AI Package Became A Credential Stealer
Cryptonomist: AI Supply Chain Breach Exposes 2,500+ Companies
Gadgets360: CloudSEK Identifies AI Supply Chain Exposure
PRNewswire: CloudSEK Identifies More than 2,500 Organizations
Unite.ai: CloudSEK Links March LiteLLM Supply Chain Breach
Infostealers.com: Largest AI Supply Chain Breach of 2026
CyberKendra: LiteLLM Breach Exposed 434,000 CI/CD Pipelines
PlainSec: LiteLLM Breach Grew Into CI Secret Spill
Recatools: LiteLLM Supply Chain Attack: 434,000 Pipelines
The Hacker News: Malicious LiteLLM Releases Tied to Trivy Hack
CSA Research Note: TeamPCP's LiteLLM Backdoor
Ars Technica: Terabytes of credentials leaked in massive supply-chain attack
Dev.to: The 40-Minute Supply Chain Attack
CloudSEK Blog: 2,500+ Companies and 434,000 CI/CD Pipelines Exposed
SecureInSeconds: LiteLLM supply-chain leak
CSA Research Note: LiteLLM CVE-2026-42208