AI Infrastructure Supply Chain Attack: LiteLLM Breach Analysis

Summary
n March 2026, threat group Team PCP compromised LiteLLM Python packages (v1.82.7/v1.82.8) via a hijacked upstream scanner token. The SANDCLOCK malware executed automatically on Python startup, harvesting cloud keys, Kubernetes secrets, and AI credentials across 2,500+ organizations and 434,000 CI/CD pipelines.
Key Insights
- Zero-Import Execution: Executed automatically via .pth files without requiring import litellm.
- Memory Scraping: Extracted masked GitHub secrets from /proc/<pid>/mem and IMDS endpoints.
- Upstream Cascade: Exploited an unpinned Trivy scanner dependency to poison the release pipeline.
- Self-Leaking Repos: Created public GitHub repos on victim accounts when direct exfiltration failed.
- Ongoing Risk: Stolen credentials remain active targets per FBI Advisory FLASH-20260702-01.
Access Resources
Explore trusted sources and additional references related to this article.
About the Author

Christian Blem Charity
Senior AI Product Leader and ex-Deloitte consultant focused on enterprise AI and automation.
Phil Slorick is an operational architect focused on helping organizations integrate artificial intelligence into core business processes. His expertise includes workflow automation, operational efficiency, enterprise systems, and scalable AI implementation. He writes about practical AI adoption, business operations, digital transformation, and building intelligent organizations.