Stolen AI gateway packages exposed secrets at 2,100 organizations

A CloudSEK dataset maps the March LiteLLM poisoning campaign to secret exposure at thousands of organizations.

CSBadmin
2 Min Read

Two poisoned releases of the LiteLLM AI gateway that lingered on PyPI for about 40 minutes in March may have exposed credentials at thousands of organizations. The exposure mapping comes from a dataset published by threat intelligence firm CloudSEK.

Versions 1.82.7 and 1.82.8 of the open-source gateway carried credential-stealing code built to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. In version 1.82.8, a file named litellm_init.pth ran at interpreter startup, so any Python process starting in that environment triggered the payload, whether or not the software imported LiteLLM. Stolen data was sent to models.litellm[.]cloud, a domain controlled by the attackers.

The dataset behind the mapping holds roughly 434,000 captured files. CloudSEK links potential exposure to more than 2,500 organizations while stressing the total is not a victim count. NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp are among the entries. The lookup is public and searchable by name or domain with confidence labels.

The incident belongs to the wider TeamPCP supply chain campaign connected to the compromise of Aqua Security’s Trivy scanner, tracked as CVE-2026-33634 and added to CISA’s Known Exploited Vulnerabilities catalog in March. An FBI advisory from July warned that actors tied to the campaign may weaponize stolen credentials long after the initial breach.

CloudSEK and LiteLLM both recommend rotating credentials rather than waiting for proof of misuse. The FBI also lists repositories named tpcp-docs or docs-tpcp as campaign indicators to hunt for.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.