AI Infrastructure Supply Chain Attack: LiteLLM Breach Analysis

August 11, 2026
By Christian Blem Charity
AI Infrastructure Supply Chain Attack: LiteLLM Breach Analysis

Summary

n March 2026, threat group Team PCP compromised LiteLLM Python packages (v1.82.7/v1.82.8) via a hijacked upstream scanner token. The SANDCLOCK malware executed automatically on Python startup, harvesting cloud keys, Kubernetes secrets, and AI credentials across 2,500+ organizations and 434,000 CI/CD pipelines.

Key Insights

  • Zero-Import Execution: Executed automatically via .pth files without requiring import litellm.
  • Memory Scraping: Extracted masked GitHub secrets from /proc/<pid>/mem and IMDS endpoints.
  • Upstream Cascade: Exploited an unpinned Trivy scanner dependency to poison the release pipeline.
  • Self-Leaking Repos: Created public GitHub repos on victim accounts when direct exfiltration failed.
  • Ongoing Risk: Stolen credentials remain active targets per FBI Advisory FLASH-20260702-01.

About the Author

Christian Blem Charity

Christian Blem Charity

Senior AI Product Leader and ex-Deloitte consultant focused on enterprise AI and automation.

Phil Slorick is an operational architect focused on helping organizations integrate artificial intelligence into core business processes. His expertise includes workflow automation, operational efficiency, enterprise systems, and scalable AI implementation. He writes about practical AI adoption, business operations, digital transformation, and building intelligent organizations.