{"slug": "2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach", "title": "2,500 Companies and 434,000 Pipelines Exposed – Largest AI Supply Chain Breach", "summary": "CloudSEK's research on the LiteLLM AI supply-chain attack found that 2,500+ organizations and 434,000 CI/CD pipelines were potentially exposed, with the threat actor group Team PCP compromising the AI infrastructure in March 2026. The FBI's July 2026 FLASH advisory warns that affiliated actors may weaponize harvested credentials, and affected organizations include Robert Bosch GmbH, London Stock Exchange Group, Thomson Reuters, FedEx, and X Corp.", "body_md": "2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026\n\nCloudSEK’s latest research examines the LiteLLM AI supply-chain attack, which potentially exposed 2,500+ organisations and 434,000 CI/CD pipelines worldwide. The report details the risks to cloud credentials, source-code repositories, Kubernetes environments and AI infrastructure, while highlighting how compromised AI dependencies can create enterprise-wide security exposure.\n\nGet the latest industry news, threats and resources.\n\nNo items found.\n\nExecutive Summary\n\nIn March 2026, the threat actor group Team PCP orchestrated what is believed to be the largest supply chain attack targeting AI infrastructure by compromising LiteLLM. CloudSEK Threat Intelligence was able to get access to the victim information and is disclosing the details of all the impacted victims .\n\nWe are sharing this openly so that every affected organization can act proactively The threat is still live: the FBI's July 2026 FLASH advisory (FLASH-20260702-01) warns that affiliated actors are likely to weaponize the harvested credentials long after the original intrusion, which means further supply chain attacks remain a real possibility. Early awareness is the strongest defense; knowing you were impacted lets you rotate credentials, close the exposure, and harden before the next campaign hits.\n\nAttacks on AI infrastructure are on the rise and that is exactly what CloudSEK AIvigil, our AI Attack Surface Monitoring platform, is built to prevent. AIvigil continuously discovers, monitors, and secures exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows, and shadow AI. We combine the power of cyber threat intelligence and AI exposure to detect and prevent cyberattacks on AI infrastructure.\n\nThose exposed range from large AI companies and model providers to cybersecurity vendors, SaaS platforms, and enterprises worldwide.\n\ncompanies in CloudSEK's reconstructed\nexposure dataset\n\n434,000\n\nCI/CD pipelines potentially exposed\n\n40 min\n\napproximate period the affected PyPI\npackages were live\n\nVICTIM EXPOSURE DATA\n\nSelected High-Confidence Organizations in the Exposure Dataset\n\nThe records below are the leading organization-level matches supplied for this report. High confidence refers to the strength of the exposure match,not proof of successful compromise or attacker use.\n\n“Secrets” and “Runs” are reproduced as aggregate counts from the supplied dataset. Domains are shown only where provided. No secret values, credentials, internal paths, or personal information are included.\n\nSelected High-Confidence Organizations — continued\n\nOrganization / domain\n\nSecrets\n\nRuns\n\nConfidence\n\nRobert Bosch GmbH\n—\n\n1\n\n1\n\nHigh\n\nLondon Stock Exchange Group (LSEG)\nlseg.com\n\n48\n\n241\n\nHigh\n\nThomson Reuters\nthomsonreuters.com\n\n0\n\n36\n\nHigh\n\nFedEx\nfedex.com\n\n164\n\n147\n\nHigh\n\nMunich Re\nmunichre.com\n\n110\n\n62\n\nHigh\n\nMediaTek Inc.\nmediatek.com\n\n126\n\n119\n\nHigh\n\nVolkswagen AG\nvolkswagenag.com\n\n0\n\n2,242\n\nHigh\n\nDeloitte\ndeloitte.com\n\n462\n\n503\n\nHigh\n\nThe Kroger Co.\nkroger.com\n\n95\n\n35\n\nHigh\n\nSiemens Energy\nsiemens-energy.com\n\n0\n\n36\n\nHigh\n\nThales Group\nthalesgroup.com\n\n146\n\n266\n\nHigh\n\nX Corp (Twitter)\ntwitter.com\n\n3,459\n\n1,153\n\nHigh\n\nZscaler, Inc.\nzscaler.com\n\n65\n\n304\n\nHigh\n\nEpic Games\nepicgames.com\n\n62\n\n31\n\nHigh\n\nSelected High-Confidence Organizations , continued\n\nOrganization / domain\n\nSecrets\n\nRuns\n\nConfidence\n\nOrange S.A.\norange.com\n\n180\n\n5,642\n\nHigh\n\nHP Inc.\nhp.com\n\n1\n\n18\n\nHigh\n\nPhilips\nphilips.com\n\n5\n\n6\n\nHigh\n\nFortum Oyj\nfortum.com\n\n823\n\n455\n\nHigh\n\nVodafone Group Plc\nvodafone.com\n\n83\n\n51\n\nHigh\n\nCarl Zeiss AG\nzeiss.com\n\n119\n\n178\n\nHigh\n\nDeutsche Bahn AG\n,\n\n25\n\n35\n\nHigh\n\nNGINX, Inc.\nnginx.com\n\n267\n\n269\n\nHigh\n\nBT Group\nbt.com\n\n216\n\n325\n\nHigh\n\nLiebherr\nliebherr.com\n\n98\n\n20\n\nHigh\n\nKrungthai Bank Public Company Limited\nkrungthai.com\n\n614\n\n604\n\nHigh\n\nRoku, Inc.\nroku.com\n\n61\n\n51\n\nHigh\n\nInterpretation requirement\n\nA high-confidence organization match should trigger private validation, notification, credential review, and log investigation. Public wording should remain “potentially exposed” unless malicious execution, exfiltration, unauthorized access, or downstream use has been independently verified.\n\nDATA AT RISK\n\nWhat matters for victims\n\nThe stolen object was Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys could allow attackers to move far beyond the affected package.\n\nRemoval does not end the incident. A package can disappear in minutes while copied credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated.\n\nAutomated pipelines amplify a brief compromise. CI/CD systems install dependencies at machine speed and often run with broad privileges, making a short publication window operationally significant.\n\nAI infrastructure is becoming a strategic target. Gateways, agents, vector stores, model endpoints, and MCP servers sit between sensitive data and systems capable of taking action.\n\nActor context is secondary. Public reporting attributes the campaign to Team PCP; this report limits actor discussion to what defenders need for attribution and response.\n\nImportant interpretation\n\nThe 2,500+ company and 434,000 pipeline figures describe reconstructed exposure.\nThey should not be read as proof that every listed organization was successfully\ncompromised or that every credential was stolen.\n\nThe Scale of Exposure\n\nWhat was taken\n\nOn every compromised CI runner, TeamPCP's stealer (tracked by Google as SANDCLOCK) escalated to root and swept:\n\nSSH keys\n\nAWS, GCP, and Azure credentials\n\nKubernetes tokens\n\n.env files and CI/CD secrets — including the values GitHub Actions tries to mask, scraped directly from /proc/<pid>/mem\n\nFor AI builds specifically: LLM API keys and gateway configuration — the credentials to an organization's entire AI stack\n\nCloud keys were read straight from the instance metadata service (IMDS) and Kubernetes tokens from mounted service-account paths , no exploit needed, just the access each runner already carried. The collected data was then sealed with AES-256 under a hard-coded RSA-4096 key, so even intercepted traffic stayed unreadable without the actor's private key\n\nThe loot was encrypted and shipped to a typosquatted domain. Where exfiltration failed, the malware created a public repository inside the victim's own GitHub account and uploaded the stolen data there as a release asset , meaning some organizations were leaking their own secrets into public view without knowing it\n\nVICTIM EXPOSURE\n\nThe Exposure: Organizations, Pipelines, and Downstream Systems\n\nHow exposure can become business impact\n\n1. Affected artifact —\nA compromised package or dependency enters a build or developer environment.\n\n2. Secret access —\nThe process reads credentials, tokens, keys, configuration, and runtime data available to that host.\n\n3. Privilege expansion —\nStolen access reaches repositories, registries, clusters, cloud accounts, SaaS tenants, or AI providers.\n\n4. Downstream loss —\nAttackers can steal code and data, publish poisoned packages, persist, disrupt services, or extort the victim.\n\nWhat victim-level disclosure should contain\n\nField\n\nWhy it matters\n\nOrganization and affected domain/project\n\nResolves the exposure to the correct security owner and avoids ambiguous naming.\n\nObserved pipeline or dependency evidence\n\nSeparates direct evidence from inference and supports reproducible validation.\n\nCredential classes potentially accessible\n\nDetermines which keys, tokens, service accounts, and sessions must be rotated.\n\nExposure window and last-known activity\n\nDefines the log-search period and the minimum investigation scope.\n\nNotification and remediation status\n\nTurns disclosure into measurable risk reduction rather than a static list.\n\nWhat Was at Risk Inside the Exposed Environments\n\nThe value of the breach lies in what the affected process could read, not merely in the package name.\n\nLiteLLM commonly operates close to model providers, application services, and deployment systems. In CI/CD and developer environments, the same host may also hold credentials for source control, cloud infrastructure, registries, containers, and production services. The categories below are potential exposure classes when present on an affected system.\n\nExposure class\n\nExamples\n\nPotential consequence\n\nCloud credentials\n\nAWS, GCP, Azure keys and metadata-service tokens\n\nAccount takeover, data access, compute abuse, persistence\n\nPrivate repositories, builds, images, model assets\n\nIP theft, backdoors, release tampering\n\nWhy credential rotation must be broad\n\nRotating only the LiteLLM or model-provider key is insufficient. Any credential readable by the affected process, present in process memory, injected into the job, stored on disk, or retrievable through an instance metadata service should be treated as potentially exposed until validated.\n\nATTACK PATH\n\nFrom a Trusted Package to Enterprise Access\n\nThe March incident illustrates how an AI component can become an entry point into the wider software and cloud estate.\n\n1. Upstream compromise:\nThe release process's trusted security scanner (Trivy) was taken over. A leaked automation token , rotated but not fully revoked , left an approximately 20-day window in which the attacker force-pushed malicious code over the scanner's published version tags, so downstream builds pulling those tags received poisoned code that still looked legitimate.\n\n2. Poisoned LiteLLM release:\nVersions 1.82.7 and 1.82.8 are published to PyPI during a short exposure window.\n\n3. Automatic execution:\nA malicious .pth file runs when Python starts,no explicit LiteLLM import is required. Because a .pth file executes at interpreter startup rather than on import, the payload ran wherever the package was merely installed , sidestepping the --ignore-scripts protection teams rely on to keep installs safe.\n\n4. Secret collection:\nCredentials and environment data available to the process can be harvested.\n\n5. Downstream access:\nRepositories, cloud accounts, clusters, registries, SaaS, and AI services become reachable.\n\n6. Persistence and reuse:\nStolen access can be sold, reused, or weaponized after the malicious package is removed.\n\nHow the poison reached LiteLLM\n\nLiteLLM was never attacked directly. Its CI pipeline installed the Trivy scanner unpinned from the system package manager (apt), so the compromised scanner flowed into the build automatically, and that build produced and published the malicious 1.82.7 and 1.82.8 releases to PyPI. Trivy, then the build system, then the LiteLLM release: one un-revoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure.\n\nA 40-minute package window can create a months-long incident\n\nAutomated build systems compress time. Once a malicious artifact reaches a registry, scheduled jobs, dependency resolvers, ephemeral runners, developer laptops, and cached layers can copy it rapidly. The forensic and credential-rotation window therefore extends beyond package removal.\n\nAI INFRASTRUCTURE RISK\n\nWhy the Next Supply Chain Wave Will Target AI Infrastructure\n\nCloudSEK assessment: AI systems are becoming high-value junctions between data, identity, compute, and autonomous action.\n\nIn the industrial age, rail junctions became strategic targets because many supply routes met at one point. AI gateways, agent runtimes, MCP servers, and vector stores are becoming the junctions of digital operations.\n\nPrivileged position. AI gateways and agent runtimes often hold credentials for models, databases, plugins, cloud services, and internal tools.\n\nWide dependency graph. Modern AI stacks combine open-source packages, hosted models, SDKs, extensions, connectors, vector databases, and third parties.\n\nAutonomous execution. Agentic workflows can read, write, call tools, and trigger business processes, increasing the blast radius of stolen access.\n\nRapid and shadow adoption. Teams deploy AI services faster than central security inventories are updated, leaving unknown assets and unmanaged credentials.\n\nHigh-value data. Prompts, retrieval stores, training data, model outputs, and connected business systems concentrate sensitive information.\n\nTraditional visibility gaps. Conventional attack surface tools see endpoints and ports but often miss model, agent, MCP, prompt, and AI workflow context.\n\nThe lesson of LiteLLM\n\nThe incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else.\n\nVICTIM RESPONSE\n\nImmediate Actions for Potentially Exposed Organizations\n\nResponse should assume credential exposure first, then use evidence to reduce the scope.\n\n0–24 hours\n\n24–72 hours\n\nOngoing controls\n\nIdentify use of LiteLLM 1.82.7/1.82.8 and affected build windows.\nIsolate affected runners, hosts, images, and caches.\nRotate every credential accessible to the affected process,\nincluding cloud, repository, registry, Kubernetes, SaaS,\ndatabase, and AI keys.\n\nRebuild affected environments from known-clean sources.\nHunt for unexpected repositories such as\ntpcp-docs/docs-tpcp, suspicious egress, unauthorized tokens,\nand new service accounts.\nReview cloud, source-control, package registry, and cluster audit logs.\n\nPin dependencies and GitHub Actions to verified hashes.\nShorten credential lifetime and scope; prefer workload identity\nover static keys.\nMonitor CI/CD runtime behavior and third-party AI dependencies\ncontinuously.\nInventory AI assets and owners.\n\nInvestigation questions that determine real victim impact\n\nWas an affected artifact downloaded, cached, executed, or merely referenced?\n\nWhich secrets were present in environment variables, process memory, files, metadata services, or injected job contexts?\n\nDid any token show use from an unusual IP, device, geography, runner, or user agent after the exposure window?\n\nCould stolen publishing credentials have created a second-generation supply chain compromise?\n\nDid the affected AI gateway connect to sensitive prompts, vector stores, agents, internal tools, or customer data?\n\nDo not wait for proof before rotating high-value secrets\n\nA lack of obvious malicious activity is not evidence that a credential was not copied. For credentials with production reach, the cost of rotation is usually lower than the cost of delayed containment.\n\nCLOUDSEK AIVIGIL\n\nFrom Incident Response to Continuous AI Exposure Management\n\nCloudSEK AIVigil is built to discover and monitor the AI attack surface and supply chain attacks before exposed infrastructure becomes an attack path.\n\nAIVigil continuously discovers, monitors, and secures exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows, and shadow AI. It combines CloudSEK's cyber threat intelligence with AI exposure monitoring so security teams can connect an external signal to the AI asset, credential, dependency, and business system at risk.\n\nSecurity blind spot\n\nHow AIVigil addresses it\n\nUnknown AI assets\n\nContinuous outside-in discovery and AI Bill of Materials (AI-BOM)\n\nExposed AI services\n\nMonitoring of model endpoints, gateways, vector databases, GPU infrastructure, and cloud AI misconfigurations\n\nLeaked AI credentials\n\nThreat intelligence correlation across credential leaks, repositories, malware logs, and external sources\n\nMCP and agentic risk\n\nAssessment of MCP servers, tool access, agent permissions, and workflow exposure\n\nShadow AI\n\nDiscovery of unmanaged AI applications and services operating outside approved inventory\n\nPrioritization gap\n\nRisk scoring based on authentication, reachability, agent agency, blast radius, and live threat signals\n\nThe continuous loop\n\n1. Discover:\nFind AI assets and shadow AI.\n\n2. Scan:\nAssess exposures and attack paths.\n\n3. Triage:\nCorrelate with live threat intelligence.\n\n4. Report:\nDrive ownership and remediation.\n\nThe objective\n\nMove from learning about an AI infrastructure breach after credentials are stolen to continuously knowing which AI assets exist, what they expose, and which attack paths require action now.\n\nMETHODOLOGY AND SCOPE\n\nMethodology, Confidence, and Responsible Interpretation\n\nCloudSEK’s Threat Intelligence team obtained the exposure data through its intelligence sources, including records relating to organizations, CI/CD pipelines, and credential/token exposures associated with the March 2026 supply-chain cascade involving compromised Trivy, Checkmarx KICS, and LiteLLM builds\n\nThe exposed AI and cloud assets those credentials reach , model endpoints, gateways, vector databases, GPU infrastructure, cloud accounts, and MCP/agentic workflows\n\nThe three weaponized tool vectors that produced the exposure: Trivy, Checkmarx KICS, and LiteLLM\n\nPublic advisories confirming the campaign and affected tooling: FBI FLASH, Aqua Security, Checkmarx, LiteLLM/BerriAI, Unit 42, and Sophos\n\nRecommended confidence labels for the victim dataset\n\nLabel\n\nMeaning\n\nRecommended wording\n\nExposed\n\nEvidence links the organization or pipeline to an affected artifact or exposure path.\n\nPotentially exposed; validation required.\n\nProbable compromise\n\nExecution or credential-access evidence exists, but attacker use is not confirmed.\n\nLikely affected; containment and investigation required.\n\nConfirmed compromise\n\nMalicious execution, exfiltration, unauthorized access, or downstream use is verified.\n\nConfirmed victim; incident response active.\n\nAttribution in one paragraph\n\nPublic reporting attributes the broader campaign to the financially motivated cluster Team PCP. The actor compromised trusted security and developer tooling and used credential-stealing payloads to reach cloud and CI/CD environments. The identity, internal disputes, forum affiliations, and leadership history of the group are not required to understand victim exposure and are intentionally excluded from the main narrative.\n\nSOURCES AND CONCLUSION\n\nCloudSEK AIVigil- AI Attack Surface Monitoring\n\nAttacks on AI infrastructure are on the rise and that is exactly what CloudSEK AIvigil, our AI Attack Surface Monitoring platform, is built to prevent. AIvigil continuously discovers, monitors, and secures exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows, and shadow AI. We combine the power of cyber threat intelligence and AI exposure to detect and prevent cyberattacks on AI infrastructure.", "url": "https://wpnews.pro/news/2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach", "canonical_source": "https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines", "published_at": "2026-08-11 09:48:42+00:00", "updated_at": "2026-08-11 10:11:47.985208+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-infrastructure"], "entities": ["CloudSEK", "LiteLLM", "Team PCP", "FBI", "Robert Bosch GmbH", "London Stock Exchange Group", "Thomson Reuters", "FedEx"], "alternates": {"html": "https://wpnews.pro/news/2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach", "markdown": "https://wpnews.pro/news/2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach.md", "text": "https://wpnews.pro/news/2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach.txt", "jsonld": "https://wpnews.pro/news/2500-companies-and-434000-pipelines-exposed-largest-ai-supply-chain-breach.jsonld"}}