A compromised open-source Trivy scanner infected LiteLLM through its CI pipeline, exposing more than 2,500 organisations and 434,000 CI/CD pipelines to potential credential theft.
More than 2,500 organisations and 434,000 CI/CD pipelines were exposed in an open-source software supply-chain attack involving LiteLLM, according to CloudSEK. The attack demonstrates how a compromised dependency can cascade through interconnected open-source development and distribution infrastructure.
Threat actor TeamPCP did not directly target LiteLLM. Instead, its CI pipeline automatically installed a compromised version of Trivy, Aqua Security’s open-source vulnerability scanner. The compromise then moved from Trivy to the LiteLLM build system and into two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, published to PyPI.
“Trivy, then the [LiteLLM] build system, then the LiteLLM release: one unrevoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure,” CloudSEK said.
The malicious packages were available for about 40 minutes, but their code executed on every Python invocation without requiring an explicit import. The payload potentially exposed package-publishing credentials, cloud keys, SSH keys, tokens, environment variables, runtime data and AI-provider keys.
CloudSEK stresses that the 2,500+ organisations and 434,000 pipelines represent reconstructed exposure, not confirmed compromise. Potentially affected organisations include Nvidia, AWS, Samsung, Salesforce, Cisco, Siemens, HP and Zscaler.
The incident highlights the interconnected attack surface spanning open-source repositories, CI/CD systems, dependencies and package registries. CloudSEK also warns that AI infrastructure could become a growing supply-chain target because it connects data, identity, compute and autonomous action.















































































