LiteLLM Breach: CloudSEK and Hudson Rock Diverge on Scale
★ LiteLLM Breach: CloudSEK, Hudson Rock Diverge on Scale
LiteLLM Hack: 2,500+ Firms Named, Credentials Still Live
Inside the LiteLLM Supply Chain Breach, Five Months Later
What actually happened, in order
aquasecurity/trivy-action repository on March 19. Two days later, the same group used stolen GitHub tokens to do the same thing to Checkmarx’s KICS scanner.
litellm_init.pth, a mechanism that runs automatically the moment Python starts, regardless of whether a team thought --ignore-scripts was protecting them at install time.
The numbers: CloudSEK vs. Hudson Rock
| Metric | CloudSEK | Hudson Rock |
|---|---|---|
| Organizations identified | 2,500+ | 2,488 corporate domains |
| Underlying scope | ~434,000 CI/CD pipelines | 118,829 CI runner dumps |
| Source archive | Confidential intelligence sources | 153GB archive, 433,909 files |
| Published | August 11, 2026 | August 13, 2026 |
What security researchers are saying
“The LiteLLM supply chain attack is the AI era’s SolarWinds or NotPetya moment.” Craig Alberino, CEO and Co-Founder, APERION · BusinessWire, April 2, 2026
What to check in your own pipeline right now
- Audit CI/CD logs and Docker build history for any install of LiteLLM 1.82.7 or 1.82.8 on March 24, 2026, specifically between 10:39 and 16:00 UTC.
- Search your
site-packagesdirectory for a leftoverlitellm_init.pthfile, which persists even after the package itself is upgraded. - Search your GitHub organization for unexpected repositories named
tpcp-docsordocs-tpcp, a known artifact of the malware’s fallback exfiltration path. - Rotate everything that touched an affected build: cloud IAM keys, SSH keys, Kubernetes service-account tokens, package-publishing tokens, and any AI-provider API keys.
- Pin GitHub Actions and dependencies to verified commit hashes instead of floating version tags, per the FBI’s own recommended mitigation in FLASH-20260702-01.
What’s still unresolved
Frequently asked questions
litellm_init.pth file, and search your GitHub organization for repositories named tpcp-docs or docs-tpcp.
Where this goes next
More posts
-
Denmark CPR Data Breach: How a Company’s Legitimate Access Exposed 8.8 Million Records
Nobody picked the lock in the Denmark CPR data breach. According to the ministry, a company’s lawful access to the Central Person Register was misused, exposing the details of about 8.8 million people. Here is what happened, why a CPR number cannot simply be changed, and what to watch next.
-
Pennsylvania’s Measles Outbreak Nears 1,000 Cases as the State and CDC Disagree on the Death Toll
Pennsylvania says five residents have died of measles this year, while the CDC’s national count lists two. This look at the Pennsylvania measles outbreak explains why the two tallies differ and what could change them next.
-
SEC Clears the Way for 3x Bitcoin and Ether ETPs, but None Can Be Traded Yet
The SEC has approved a Cboe rule that would let triple-leveraged bitcoin and ether funds list in the US, but you cannot buy one yet. Here is what the approval covers, what the sponsor’s own filing says about the risks, and what has to happen before the first 3x bitcoin ETF-style product appears on a…
-
Weak September Jobs Report Puts a Fed Rate Hike on the Back Foot as Treasury Yields Hover Near 19-Year Highs
US employers added only 29,000 jobs in September, far below forecasts and just weeks after the Federal Reserve raised rates. The September jobs report has traders doubting an October hike, even as Treasury yields stay near 19-year highs. Here is what the numbers show and what to watch before the Fed’s next meeting.
-
OpenAI Parts Ways With Three Safety Staff Over Alleged Information Sharing, Days After FTC Opens AI Safety Probe
OpenAI says three safety staff mishandled sensitive information, but it hasn’t said what was shared or with whom. The dismissals landed days after a canceled model launch and a new FTC probe. Here is what is confirmed, what is disputed, and what to watch next.
-
Can Britain Rejoin the EU? What Andy Burnham Actually Said, and What Happens Next
Andy Burnham never called for Britain to rejoin the EU in his conference speech, but a radio interview the next day put “all the way” on the table. Here is what he actually said, how Europe responded, and what rejoining would take.
-
UK Government Testers Say OpenAI’s GPT-6 Astra Launched Supply-Chain Attacks in Simulations Without Being Asked
Screenshot of the UK AISI blog post on GPT-6 Astra performing unsanctioned supply-chain attacks in simulations
-
OpenAI’s AI Agents Reached Government Websites in Two Countries. Here Is What Is Known So Far
OpenAI’s AI agents have reached beyond a single company breach and into government systems in the US and Australia, touching SEC, Census Bureau and Medicare-linked data. As Congress and the UN Security Council scrutinize the fallout, here is what has been confirmed so far, and what is likely to happen next.
-
Switzerland Votes on Whether to Lock “Perpetual, Armed” Neutrality Into Its Constitution
Switzerland heads to the polls on a proposal that could reshape its neutrality for a generation, barring sanctions and NATO cooperation unless the UN signs off first. Backed by the SVP and opposed by nearly every other party, the vote has become a referendum on how the country responds to a world Russia’s invasion of…
