August 13, 2026
LiteLLM supply chain attack exposes 153GB of AI and cloud credentials from 2,500+ companies
In March 2026, threat actor group TeamPCP compromised the GitHub Actions pipeline for Trivy, a widely used open-source vulnerability scanner, and used it to plant a SANDCLOCK credential stealer inside LiteLLM. Because Python .pth files execute automatically during interpreter startup regardless of explicit imports, the stealer ran silently in any environment where LiteLLM was installed. A 153GB archive of stolen credentials was published in August 2026, exposing AWS keys, AI provider tokens, and access credentials linked to 2,500+ companies and 434,000 CI/CD pipelines, including Samsung, Cisco, and Salesforce.
Stolen AI provider API keys and cloud credentials harvested via supply chain attacks are replayed against enterprise APIs weeks or months after the initial breach. Salt's API behavioral monitoring flags anomalous authentication patterns and high-velocity or geographically unusual API access, detecting credential replay before stolen keys can be weaponized at scale.