A cybersecurity analysis by CloudSEK revealed the scale of the March 2026 LiteLLM supply-chain attack, which exposed about 434,000 CI/CD pipelines at more than 2,500 companies worldwide. Continuous Integration (CI) and Continuous Delivery (CD) pipelines are automated workflows that build, test, and deploy software from a developer’s environment to production users. Although the malicious packages were active for only about 40 minutes, the breach may have exposed critical credentials and security tokens across numerous major organizations.[1]
CloudSEK's investigation has identified high-confidence exposure matches associated with prominent global corporations. The affected organizations include technology giants NVIDIA, Samsung, and Cisco; industrial leader Siemens; professional services firm Deloitte; telecommunications provider Vodafone; social media platform X; cybersecurity company Zscaler; and financial information provider S&P Global, among many others. The breadth of the victim list demonstrates how supply-chain vulnerabilities can rapidly cascade across diverse industries and sectors, affecting companies regardless of their size or security sophistication.
Compromised environments potentially exposed multiple categories of sensitive information critical to modern cloud-based operations. These include cloud credentials for major providers, source-code access permissions, Kubernetes tokens used for container orchestration, CI/CD secrets that automate software deployment, and LLM/API keys that enable access to artificial intelligence services and other application programming interfaces. Each category of exposed credentials represents a different avenue for exploitation, from unauthorized access to proprietary source code to hijacking cloud infrastructure resources.
Security experts have emphasized that the brief 40-minute window during which the malicious packages were active does not reflect the true duration of the threat. The larger concern centers on the longevity of stolen credentials, which can remain functional even after the compromised package has been identified and removed from systems. This creates the possibility of follow-on attacks occurring well beyond the original incident. Attackers who harvested credentials during the brief exposure window may retain access to affected systems indefinitely unless organizations identify and rotate all potentially compromised secrets.
The incident highlights the inherent vulnerabilities in modern software supply chains, where a single compromised dependency can affect thousands of downstream users within minutes. The attack targeted LiteLLM, a tool commonly used in AI and machine learning workflows, demonstrating how attackers increasingly focus on widely adopted open-source components to maximize their impact. CI/CD pipelines, which automate the building, testing, and deployment of software, represent particularly attractive targets because they typically require broad access to credentials and infrastructure to function.
A CloudSEK spokesperson commented, “The significance of the LiteLLM incident is not just the compromise itself, but the scale of potential downstream exposure. CloudSEK’s analysis identified more than 2,500 organizations and around 434,000 CI/CD pipelines that may have been exposed, including access to cloud credentials, repository tokens, Kubernetes secrets and AI provider keys."
"The key risk is that removing the malicious package does not automatically invalidate credentials that may already have been copied; those credentials can remain usable and potentially be reused long after the original incident."
“This incident is also a broader warning for enterprises adopting AI at speed. AI gateways and related infrastructure increasingly sit at the intersection of cloud systems, source code, sensitive data and automated workflows, making them a high-value target for supply-chain attacks. Organizations need continuous visibility into their AI assets, dependencies and credentials, rather than treating AI security as a standalone application issue,” they concluded.
CloudSEK has made available a free exposure checker tool to help organizations determine whether their systems were affected by the breach. The tool lets companies assess potential exposure without extensive manual investigation of dependency chains and deployment histories. Security researchers recommend that all organizations using LiteLLM during the March 2026 timeframe conduct thorough audits of their credential usage and implement comprehensive rotation of potentially affected secrets, regardless of whether immediate compromise is detected.
Interested in protecting your own supply chain from cyber threats? Please visit https://www.redskyalliance.com/redxray
This article is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC). For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929
[1] https://www.cybersecurityintelligence.com/blog/litellm-breach-exposed-434000-pipelines-inside-40-minutes-9623.html
Comments