CloudSEK has announced that it has identified more than 2,500 organisations that may have been potentially affected by a major AI supply chain incident involving LiteLLM in March 2026, with approximately 434,000 automated software-development pipelines linked to the exposure. LiteLLM is an open-source tool widely used to connect applications with AI models.
2,500+ organisations potentially affected by LiteLLM supply chain exposure.
434,000 CI/CD pipelines linked to the exposure.
Affected organisations include NVIDIA, Samsung, Cisco, Siemens, ServiceNow, and Deloitte.
Potentially exposed credentials include AWS, Azure, Google Cloud keys, SSH keys, and AI API keys.
Malicious versions were available on PyPI for approximately 40 minutes.
CloudSEK released free exposure-checking tool for organisations.
The incident occurred in March 2026 after cybercriminal group Team PCP compromised LiteLLM. Malicious versions of LiteLLM were reportedly available through the Python software repository PyPI for only around 40 minutes. Despite the short window, CloudSEK's analysis identified approximately 434,000 CI/CD pipelines potentially connected to the exposure. CI/CD pipelines can automatically download software packages without a developer manually reviewing every component, making it possible for a malicious package to spread across large numbers of corporate systems very quickly.
CloudSEK identified several categories of sensitive information that may have been accessible from affected environments, including AWS credentials, Google Cloud credentials, Microsoft Azure credentials, source-code repository credentials, SSH keys, Kubernetes access tokens, CI/CD deployment secrets, environment variables, and LLM and AI API keys. If valid credentials were obtained, attackers could potentially access corporate cloud environments, enter internal servers, steal proprietary source code, abuse AI platforms, move deeper into corporate networks, and target customers or partners through trusted access.
The original malicious package has been removed, but the security risk may not have ended if the attackers copied credentials while the compromised package was active. Removing LiteLLM does not automatically invalidate those credentials. CloudSEK stresses that appearing in the dataset does not automatically mean that an organisation was successfully breached, but rather that information associated with the organisation was identified in the exposure and should be investigated urgently. CloudSEK has released a free exposure-checking tool to help organisations determine whether credentials or infrastructure associated with them appear in the identified dataset.
About CloudSEK
CloudSEK is an AI-native predictive cyber-intelligence company that helps organisations identify potential attack paths and exposed access before attackers exploit them. Its platform combines digital-risk protection, cyber-threat intelligence, external attack-surface monitoring, AI attack-surface monitoring, and third-party risk intelligence.