r/u_socradario

▲ 4 r/u_socradario+3 crossposts

LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies

The LiteLLM supply chain attack exposure data is in, and the 40-minute PyPI window everyone reported was the last act, not the whole story.

Our record-level analysis of 2,188 organization records found:

→ 95% of affected orgs show collection activity before the poisoned LiteLLM packages even reached PyPI on March 24
→ The actual compromise chain started 5 days earlier, tracing back to a hijacked Trivy scanner in LiteLLM's build pipeline
→ Exposure spans 6 CI/CD platforms, not just GitHub Actions
→ The credential mix goes well beyond AI keys: Stripe payment keys, Twilio/SendGrid tokens, and npm/Docker publishing credentials all turned up in the dataset
→ Harvested data is already being brokered on Telegram, bundled with two other TeamPCP campaign stages

LiteLLM is a transitive dependency of MLflow, CrewAI, DSPy, OpenHands, and Arize Phoenix, so plenty of orgs in the dataset never knowingly installed it.

Full breakdown with IOCs, remediation steps, and the exposure dataset methodology on our blog.

reddit.com
u/socradario — 7 days ago