Affected Technology
litellm incidents
LiteLLM proxy and SDK package
CVE-2025-10725 Privilege Escalation Vulnerability affecting OpenShift AI
A flaw was found in Red Hat Openshift AI Service. The supported impact is full system takeover.
CVE-2026-59821 Security Incident affecting litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks Reported affected versions include 0.1.0.
153GB of stolen credentials surface after LiteLLM supply chain attack
A supply chain attack compromised LiteLLM via a poisoned Trivy dependency, leading to the deployment of malicious LiteLLM versions (1.82.7/1.82.8) that exfiltrated 153GB of corporate credentials. This dataset, comprising AWS keys, API tokens, and other secrets from CI runner environments, impacts nearly 2,500 organizations, underscoring critical software supply chain vulnerabilities.
Mercor Breach Linked to LiteLLM Attack Raises AI Supply Chain Security Concerns
Attackers executed a supply-chain attack on the open-source library LiteLLM by exploiting stolen credentials to inject malicious code into its PyPI distribution pipeline. This malware actively harvested sensitive information, including API keys and cloud credentials, from affected systems, potentially leading to the compromise of up to 4TB of data from companies like Mercor.
Backdoor Remote Code Execution Vulnerability
TeamPCP orchestrated a sophisticated supply chain attack, compromising the Trivy security scanner's CI/CD pipeline to publish malicious versions of the LiteLLM AI proxy package to PyPI. These trojanized versions deployed a multi-stage payload for credential harvesting, Kubernetes lateral movement, and persistent remote code execution.
AI Supply-Chain Compromise
LiteLLM Supply Chain Attack: 2,500+ Companies Exposed in the Largest AI Supply Chain Breach of 2026
AI Security Breach
AI training startup Mercor suffered a supply-chain attack leveraging the open-source tool LiteLLM, a software layer for managing large language model integrations, impacting thousands of companies. This breach led Meta to suspend its work with Mercor, raising significant concerns about the potential exposure of sensitive AI training data, proprietary methodologies, and contractor information.
AI Supply-Chain Compromise
Mercor was reportedly impacted by a supply chain attack involving the LiteLLM component, suggesting a potential compromise of software integrity or introduction of malicious dependencies. Due to the lack of article content, specific details regarding the exploit mechanism, a CVE, or the full impact are unavailable.
AI Supply-Chain Compromise
A widespread supply-chain attack, orchestrated by TeamPCP, injected credential-stealing malware into popular open-source projects like Trivy, KICS, LiteLLM, and Telnyx. This compromise resulted in the exfiltration of credentials and data from over a thousand downstream SaaS environments, with Mercor publicly confirming the theft of 4 TB of its data and source code.