The tampered open source AI library, used by developers to route prompts across providers, gave attackers a window into cloud keys, code tokens, and admin secrets at 2,500+ organizations.
For about 40 minutes in March, a tampered version of LiteLLM, an open-source library that routes prompts across AI providers, sat on the official Python Package Index. Every developer who pulled the package during that window also pulled a credential-stealing payload that grabbed cloud keys, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials, and AI provider keys. Ars Technica reports the haul could give attackers access to more than 2,500 organizations; CloudSEK counts 434,000 exposed CI/CD pipelines, and Hudson Rock analyzed a 195TB archive from the leak. Microsoft, Amazon, Cisco, Samsung, and Salesforce appear on a partial victim list.
LiteLLM was not the first target. The same operators also hit the Trivy vulnerability scanner, HashiCorp's KICS, and the Telnyx Python SDK, according to Cycode, and LiteLLM maintainers acknowledged a suspected supply-chain incident in March. A group calling itself TeamPCP, a teenage hacker collective, has claimed the operation. Independent researcher Kevin Beaumont told Ars Technica that "teens can run circles around orgs obsessed with rushing out AI and poor DevOps security."
The credentials were not Microsoft's or Amazon's to lose; they sat on developer machines that pulled a poisoned package. What is not yet public is how many of those keys have already been used.