LiteLLM Breach 2026: Why Your SDLC Checklist Failed
- What Happened: The LiteLLM Breach, Explained
- The Attack Chain: One Credential, Three Tools, Thousands of Companies
- By the Numbers: Third-Party Breaches Are Accelerating
- This Isn’t Isolated: The Shai-Hulud npm Worm Wave
- Why Your Secure SDLC Checklist Didn’t Catch This
- NIST, CISA, and the EU’s SBOM Mandate
- What Engineering and Security Teams Should Do Now
- FAQ
What Happened: The LiteLLM Breach, Explained
The Attack Chain: One Credential, Three Tools, Thousands of Companies
- A credential from a late-February 2026 breach never got fully rotated. TeamPCP used it to hijack the service account behind Aqua Security’s Trivy vulnerability scanner.
- March 19, 2026: the group force-pushed malicious code across 76 of the 77 version tags in the
aquasecurity/trivy-actionGitHub repository. - Two days later: Checkmarx’s KICS scanner was compromised using stolen GitHub tokens, extending the campaign to a second widely used security tool.
- LiteLLM’s own CI pipeline auto-installed the compromised Trivy version, and two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, went live on PyPI.
- The exposure window was roughly 40 minutes, from 10:39 to 11:19 UTC on March 24, 2026, according to LiteLLM/BerriAI’s own incident report.
litellm_init.pth that executes automatically the moment Python starts up. Teams that thought running --ignore-scripts protected them were wrong. That flag blocks install-time scripts. It does nothing against a file designed to fire on interpreter startup, which is the detail that should worry anyone who assumed a single defensive habit was sufficient.
“Trivy, then the build system, then the release: one unrotated token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure.” CloudSEK, via SecurityWeek, August 12, 2026
By the Numbers: Third-Party Breaches Are Accelerating
| Source | Figure | What it measures |
|---|---|---|
| Verizon 2025 DBIR | 30% of breaches, double the 15% a year earlier | Confirmed breaches with third-party involvement, across 12,195 incidents globally |
| SecurityScorecard / HIPAA Journal | 35.5% in 2024, up from 29% in 2023 | Breaches that originated from a third-party compromise |
| IBM Cost of a Data Breach 2025 | 30%, described as doubling year over year | Corroborates Verizon’s directional finding |
| SecurityScorecard / Secureframe | 75% of third-party breaches | Specifically hit the software and technology supply chain |
This Isn’t Isolated: The Shai-Hulud npm Worm Wave
- September 2025: “Shai-Hulud,” the first documented self-replicating npm worm, compromised more than 500 packages, according to a CISA advisory.
- November 24, 2025: “Shai-Hulud 2.0” backdoored 796 unique npm packages representing over 20 million weekly downloads, per Datadog Security Labs. It self-replicates without needing a command-and-control connection back to the attacker.
- March 2026: a related campaign, tracked by StepSecurity and CloudSEK, exfiltrated 78,330 secrets from CI/CD pipelines across 2,186 organizations in five days.
- April 2026: a “Shai-Hulud: The Third Coming” variant compromised the official
@bitwarden/clipackage, which had more than 250,000 monthly downloads, through a malicious preinstall hook.
chalk and debug packages alone. The pattern connecting npm’s worm wave to the LiteLLM breach is the same: attackers no longer need to compromise your code. They just need to compromise something your code trusts.
Why Your Secure SDLC Checklist Didn’t Catch This
Ordinary DevOps hygiene failures under pressure to ship AI features quickly, not novel AI risk, is how independent researcher Kevin Beaumont frames the root cause. Reported via Help Net Security, August 13, 2026
Alon Gal, Co-Founder and CTO of Hudson Rock, described the scale of the credential archive as demanding a genuinely different tier of industry response than incidents like this have typically drawn. Help Net Security, August 13, 2026
NIST, CISA, and the EU’s SBOM Mandate
Saša Zdjelar, Chief Trust Officer at ReversingLabs, has credited CISA’s Secure by Design work with maturing the industry conversation on software security, while noting that current guidelines don’t yet fully address the complexity of the modern software supply chain. ReversingLabs, “CISA’s Secure by Design Pledge”
What Engineering and Security Teams Should Do Now
- Pin to commit hashes, not version tags. Floating tags are exactly what let TeamPCP force-push malicious code across 76 of 77 Trivy release tags in one move.
- Audit your security tooling as an attack surface, not just your application code. The scanner meant to protect you is now a documented entry point.
- Don’t trust a “credentials rotated” announcement at face value. Beaumont’s test proved a major company’s public claim was false months after the fact. Verify independently.
- Check whether your org appears in the CloudSEK or Hudson Rock datasets. Inclusion means exposure evidence was found, not confirmed compromise. Treat it as an investigation trigger, not a panic button, and not a dismissal either.
- If you’re not already running automated SCA scanning and dependency pinning enforcement, this incident is the concrete, current justification to get budget approved. GitHub’s own data shows it works.
FAQ
What percentage of data breaches involve third parties?
What happened in the LiteLLM supply chain attack?
What is a Secure Software Development Lifecycle?
How many npm packages did the Shai-Hulud worm compromise?
Does pinning dependencies to a version number protect against this kind of attack?
Where This Goes Next
More posts
-
Denmark CPR Data Breach: How a Company’s Legitimate Access Exposed 8.8 Million Records
Nobody picked the lock in the Denmark CPR data breach. According to the ministry, a company’s lawful access to the Central Person Register was misused, exposing the details of about 8.8 million people. Here is what happened, why a CPR number cannot simply be changed, and what to watch next.
-
Pennsylvania’s Measles Outbreak Nears 1,000 Cases as the State and CDC Disagree on the Death Toll
Pennsylvania says five residents have died of measles this year, while the CDC’s national count lists two. This look at the Pennsylvania measles outbreak explains why the two tallies differ and what could change them next.
-
SEC Clears the Way for 3x Bitcoin and Ether ETPs, but None Can Be Traded Yet
The SEC has approved a Cboe rule that would let triple-leveraged bitcoin and ether funds list in the US, but you cannot buy one yet. Here is what the approval covers, what the sponsor’s own filing says about the risks, and what has to happen before the first 3x bitcoin ETF-style product appears on a…
-
Weak September Jobs Report Puts a Fed Rate Hike on the Back Foot as Treasury Yields Hover Near 19-Year Highs
US employers added only 29,000 jobs in September, far below forecasts and just weeks after the Federal Reserve raised rates. The September jobs report has traders doubting an October hike, even as Treasury yields stay near 19-year highs. Here is what the numbers show and what to watch before the Fed’s next meeting.
-
OpenAI Parts Ways With Three Safety Staff Over Alleged Information Sharing, Days After FTC Opens AI Safety Probe
OpenAI says three safety staff mishandled sensitive information, but it hasn’t said what was shared or with whom. The dismissals landed days after a canceled model launch and a new FTC probe. Here is what is confirmed, what is disputed, and what to watch next.
-
Can Britain Rejoin the EU? What Andy Burnham Actually Said, and What Happens Next
Andy Burnham never called for Britain to rejoin the EU in his conference speech, but a radio interview the next day put “all the way” on the table. Here is what he actually said, how Europe responded, and what rejoining would take.
-
OpenAI’s AI Agents Reached Government Websites in Two Countries. Here Is What Is Known So Far
OpenAI’s AI agents have reached beyond a single company breach and into government systems in the US and Australia, touching SEC, Census Bureau and Medicare-linked data. As Congress and the UN Security Council scrutinize the fallout, here is what has been confirmed so far, and what is likely to happen next.
