LiteLLM PyPI Hack Exposed 153GB of Data from 2,488 Organizations in 40 Minutes

A March 2025 supply chain attack on the LiteLLM PyPI package lasted roughly 40 minutes but resulted in the theft of a 153GB archive containing 433,909 files, according to analyses published by Hudson Rock and CloudSEK in August 2026. The malicious payload gained root access on compromised CI runners and harvested SSH keys, AWS, GCP, and Azure credentials, Kubernetes tokens, .env files, and LLM API keys across 2,488 corporate domains. Researchers identified 118,829 individual CI runner dumps tied to those organizations, with one unnamed company alone accounting for 17 compromised pipeline dumps exposing multiple sensitive tokens. A significant portion of the stolen records contain no company email, domain, or hostname, making attribution impossible and preventing any disclosure to the affected organizations. Hudson Rock conducted an ethical disclosure program and CloudSEK released a public lookup tool, but both efforts are limited by the absence of identifying information in many of the compromised records.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in