Last seen August 13, 2026

News report

153GB of stolen credentials surface after LiteLLM supply chain attack

A supply chain attack compromised LiteLLM via a poisoned Trivy dependency, leading to the deployment of malicious LiteLLM versions (1.82.7/1.82.8) that exfiltrated 153GB of corporate credentials. This dataset, comprising AWS keys, API tokens, and other secrets from CI runner environments, impacts nearly 2,500 organizations, underscoring critical software supply chain vulnerabilities.

Category
News
Lifecycle Status

NEW

What Happened

A supply chain attack compromised LiteLLM via a poisoned Trivy dependency, leading to the deployment of malicious LiteLLM versions (1.82.7/1.82.8) that exfiltrated 153GB of corporate credentials. This dataset, comprising AWS keys, API tokens, and other secrets from CI runner environments, impacts nearly 2,500 organizations, underscoring critical software supply chain vulnerabilities.

Why This Matters

This is source reporting of a security event, not a confirmed product vulnerability or patchable CVE. Use it as situational awareness if named organizations, cloud tenants, or identity systems overlap with yours.

Recommended Action

Read the source report. Confirm whether any named organizations, identity tenants, or cloud environments you operate are implicated. Do not treat this as a vendor advisory unless a CVE or official bulletin is attached.

Exposure

My AI Stack Exposure

Exposure unknown

Recommended Response
Last Seen

Aug 13, 2026 05:30

Exposure reason: This incident does not currently match a technology in My AI Stack.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSLiteLLMCredential ExposureData LeakageSupply ChainBerriAI/litellm

Timeline

  • Incident first seen
    Aug 13, 2026 05:30

    BugSkan first recorded this incident.

  • 153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security
    Aug 13, 2026 05:30

    helpnetsecurity.com · News

Sources

153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security

helpnetsecurity.com · Aug 13, 2026 05:30

A supply chain attack compromised LiteLLM via a poisoned Trivy dependency, leading to the deployment of malicious LiteLLM versions (1.82.7/1.82.8) that exfiltrated 153GB of corporate credentials. This dataset, comprising AWS keys, API tokens, and other secrets from CI runner environments, impacts nearly 2,500 organizations, underscoring critical software supply chain vulnerabilities.

Open publisher source

My AI Stack Match

Want personalized relevance?

Create an account to see which incidents overlap with your AI stack.

← Back to incident intelligence