
434,000 Dev Pipelines Exposed After Teenager-Led Gang Poisoned LiteLLM AI Package
Key takeaways
- LiteLLM versions 1.82.7 and 1.82.8 on PyPI were compromised, exposing 434,000 CI/CD pipelines.
- The 40-minute attack window in March captured credentials from over 2,500 organizations including Microsoft and Amazon.
- TeamPCP, a group reportedly composed largely of teenagers, has claimed responsibility for the multi-stage attack.
A coordinated supply-chain attack on LiteLLM, an open-source tool widely used to streamline AI-driven software development, has resulted in terabytes of stolen credentials belonging to some of the world's largest organizations. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the companies whose access secrets were compromised, according to security firms CloudSEK and Hudson Rock, which published their findings on Tuesday and Wednesday this week.
The attack unfolded during a 40-minute window in March when developers unknowingly downloaded poisoned versions of LiteLLM — specifically versions 1.82.7 and 1.82.8 — from the Python Package Index, the official repository for Python software. The malicious code accessed system memory on infected machines, scraped its contents, and piped the data to an attacker-controlled server. In total, researchers identified credentials across 434,000 CI/CD pipelines, the automated software delivery systems that sit at the heart of modern development workflows.
The LiteLLM compromise itself was downstream of an earlier attack targeting Trivy, a widely used open-source vulnerability scanner. The same campaign also infected KICS and the Telnyx Python SDK, suggesting the attackers deliberately targeted tools commonly found in AI-focused development environments. CloudSEK noted that Trivy's developers had rotated but failed to fully revoke an automation token over a 20-day period, giving the attackers a three-week window to push malicious code into third-party builds.
A group called TeamPCP has claimed responsibility for the attack. Researchers have largely corroborated the claim, describing the group as a loose but technically capable gang composed largely of teenagers. Independent security researcher Kevin Beaumont examined the data and confirmed its legitimacy, stating it contains a significant volume of sensitive content across victim organizations. Hudson Rock's analysis was based on a 195TB file it obtained, though neither firm has publicly identified how that file was originally sourced.
Both CloudSEK and Hudson Rock are urging affected organizations to immediately rotate all credentials, revoke cloud keys, Kubernetes service account tokens, and GitHub or GitLab personal access tokens. The firms warn that many CI/CD pipelines store credentials generically, meaning countless organizations may have active secrets sitting exposed in the breach data without yet knowing it. Early signals suggest some affected organizations have not responded with the urgency the disclosure warrants.
The bigger picture
This breach lands at a particularly awkward moment for the AI development ecosystem. Organizations across every major industry have been aggressively integrating AI tools into their software pipelines, often prioritizing speed over security hygiene. LiteLLM is exactly the kind of utility that flies beneath the radar of most security audits — it abstracts away complexity, sits quietly in the stack, and is trusted implicitly because it originates from a reputable package repository. That trust is precisely what made it an effective vector.
The competitive and regulatory implications here are significant. Cloud providers like Amazon Web Services and Microsoft Azure now face questions about how exposed keys within customer CI/CD environments could be leveraged to escalate access into their broader infrastructure. Kubernetes secrets and cloud credentials of the kind found in this dump are not merely embarrassing disclosures — they are active keys to production systems. Rivals in the AI infrastructure space, particularly companies selling secure AI deployment tooling, will likely cite this incident as evidence that open-source AI middleware carries underappreciated risk.
Perhaps most striking is the attribution. TeamPCP being described as largely teenage attackers who out-maneuvered the security posture of Fortune 500 companies is not a flattering headline for enterprise DevOps teams. It validates a concern that security researchers have raised repeatedly: the rush to ship AI features has compressed the time organizations spend vetting the third-party packages entering their pipelines. The Trivy token revocation failure — where developers rotated but did not fully revoke a credential over 20 days — is the kind of procedural gap that attackers systematically exploit. Expect this event to accelerate conversations around software supply-chain regulations and mandatory credential auditing standards.
We're covering this story because it cuts straight to one of the most consequential security blind spots in modern software development — the implicit trust placed in open-source packages that power AI tooling. At LagPing, we track how technology choices made in developer communities ripple outward into consumer products and enterprise infrastructure, and a breach touching Microsoft, Amazon, and Cisco through a single poisoned Python package is exactly that kind of ripple. What makes this especially worth your attention right now is the timing: organizations are integrating AI middleware faster than their security teams can audit it, and this incident is the clearest real-world demonstration of that risk we've seen. We also think the TeamPCP angle — a gang reportedly made up of teenagers executing a technically sophisticated multi-stage supply-chain attack — deserves honest reflection rather than dismissal. The 434,000 exposed pipelines figure is not an abstraction; those are live development systems at companies whose products many of our readers use daily. We'll be watching how affected organizations respond to the disclosure, and whether any regulatory bodies move to address supply-chain security standards in AI tooling.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like

Unpatched Macs With Screen Sharing Exposed Are Being Hijacked for Crypto Mining
Aug 15

Tech Giants Form AI Defense Pact After Rogue Model Breach Exposed Critical Security Gaps
Jul 28

Frontier AI Labs Hold Premium Pricing Ground Even as Open Source Models Flood Enterprise Pipelines
Jul 8

Amazon's $20M Water Pledge Raises Questions About Data Center Transparency
1d ago