In March 2026, threat actor group TeamPCP orchestrated what is believed to be the largest supply chain attack targeting AI infrastructure to date, compromising LiteLLM — a widely used AI gateway and orchestration library. CloudSEK Threat Intelligence gained access to victim data from the breach and is disclosing details of impacted organizations, stating the goal is to let every affected company act proactively rather than remain unaware of its exposure.
The threat remains active. The FBI's July 2026 FLASH advisory (FLASH-20260702-01) warns that actors affiliated with the campaign are likely to weaponize harvested credentials long after the original intrusion, meaning further downstream supply chain attacks remain a real possibility months after the initial compromise.
Scale of the Breach
CloudSEK's reconstructed exposure dataset spans more than 2,500 companies and approximately 434,000 CI/CD pipelines potentially exposed — despite the malicious PyPI packages behind the attack being live for only around 40 minutes. That combination — a brief publication window against a massive blast radius — is the defining characteristic of this incident.
The exposure list spans industries and company sizes, from major AI and cloud infrastructure providers to cybersecurity vendors, telecoms, automakers, banks, and industrial firms. Organizations flagged as "high-confidence" matches in CloudSEK's dataset include NVIDIA, AWS, Cisco, Samsung, Salesforce, Deloitte, Volkswagen, X Corp, S&P Global, FedEx, and dozens of others across sectors including pharmaceuticals, aerospace, telecommunications, and financial services. CloudSEK is explicit that "high confidence" refers to the strength of the exposure match — not proof that any given organization was actually compromised or that stolen credentials were used maliciously — and recommends that any organization on the list treat it as a trigger for private validation, credential rotation, and log investigation, rather than public confirmation of a breach.

What Was Actually Stolen
The compromised data includes cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider API keys — the kind of credentials that let attackers move far beyond the initially compromised package into an organization's broader cloud and CI/CD environment.
This incident illustrates three converging risks that are becoming characteristic of the AI infrastructure era, not just a one-off breach.
Speed asymmetry now favors attackers structurally. A 40-minute exposure window sounds trivial, but CI/CD pipelines install dependencies at machine speed and frequently run with broad, often over-provisioned privileges. That combination means a brief compromise at the package-registry level can fan out into hundreds of thousands of downstream pipeline executions before anyone notices — the attack doesn't need to persist to cause lasting damage, because copied credentials remain usable for weeks or months unless actively rotated. Removing the malicious package stops new exposure; it does nothing to invalidate credentials already stolen.
AI infrastructure is now a first-class attack surface, not a side channel. LiteLLM sits at a specific chokepoint — the gateway layer connecting applications, AI provider keys, and increasingly, autonomous agents. As we've discussed with the Open Secure AI Alliance's SAFE framework and the broader shift toward agentic AI, this class of infrastructure (gateways, vector databases, MCP servers, model endpoints) sits precisely between sensitive data and systems capable of taking autonomous action — making it a uniquely high-value target. A compromised AI provider key isn't just a data exposure risk; depending on what that key can invoke, it could enable an attacker to trigger real actions through an agent.
The victim list underscores that scale of adoption equals scale of exposure. The breadth of affected organizations — spanning chipmakers, cloud providers, banks, and industrial manufacturers — reflects how deeply LiteLLM-style AI gateways have already been embedded into enterprise CI/CD pipelines globally. This is the software supply chain problem (familiar from incidents like SolarWinds or the recent npm/PyPI-based attacks) recurring in a new, higher-stakes context: instead of exposing general IT infrastructure, this specific breach exposes the credentials governing AI model access, which increasingly sit closer to an organization's most sensitive automated decision-making systems.
The practical takeaway for any organization, regardless of whether it appears on CloudSEK's list: credential exposure timelines and remediation windows for AI infrastructure need to be treated with the same urgency as core cloud infrastructure — arguably more, given how quickly agentic systems are being connected to real-world actions.Waiting for a public breach confirmation before rotating potentially exposed keys is the wrong posture in an environment where the exploitation window has already closed but the credential validity window hasn't.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




