Getting your Trinity Audio player ready...

More than 2,500 organizations worldwide have been identified as potentially affected by a major artificial intelligence (AI) supply chain incident involving the open-source tool LiteLLM, putting credentials that could grant attackers access to critical business systems at risk, according to a new report from AI risk management firm CloudSEK.

The incident

In March, a cybercriminal group known as ‘Team PCP’ compromised LiteLLM, a widely used open-source tool that helps applications connect to AI models, by inserting infostealer malware directly into the LiteLLM library (a Python software repository).

The cybercriminal group compromised trusted software distribution channels by injecting malicious code into legitimate packages, thereby modifying software components. This allowed them to push trojanized updates that appeared normal but secretly installed credential-stealing malware and backdoors, giving the attackers persistent access to developer environments and systems.

Malicious versions of LiteLLM were reportedly available through the library for only about 40 minutes, but according to CloudSEK’s analysis, that brief window was enough for approximately 434,000 CI/CD pipelines to potentially be connected to the exposure.

CI/CD pipelines are automated systems that companies use to build, test, and deploy software. They can also automatically download software packages without a developer manually reviewing every component, meaning a malicious package could spread rapidly across large numbers of corporate systems.

“The incident demonstrates why software supply-chain attacks can have such a large impact,” CloudSEK said. “Attackers do not necessarily need to breach thousands of companies individually. Instead, they can target a piece of software that thousands of companies already trust and use.”

It added that the scale of the potential exposure “highlights how a single compromise in the AI software ecosystem can potentially create security consequences across thousands of businesses around the world.”

CloudSEK also warned that even after the original malicious package has been removed, the security risk may not be over; if attackers copied credentials while the compromised package was active, removing LiteLLM does not automatically invalidate those credentials.

In other words, organizations potentially exposed during the March incident could continue to face risk weeks or even months later, especially if they are unaware they’ve been hacked.

The potential victims

Based on CloudSEK’s research report, the potentially affected organizations span some of the world’s most critical industries, including technology, cybersecurity, banking and financial services, telecommunications, manufacturing, consulting, logistics, and enterprise software.

Among those exposed are market-leading names from across this spectrum, including Amazon Web Services, NVIDIA (NASDAQ: NVDA), Samsung Electronics, Cisco Systems (NASDAQ: CSCO), Siemens, S&P Global, Deloitte, Vodafone (NASDAQ: VOD), X Corp, FedEx (NASDAQ: FDX), Volkswagen, and London Stock Exchange Group.

That the list of potentially exposed organizations is over 2,500 long, with such prominent names represented, may be the attention-grabbing fact. However, according to CloudSEK “the significance of the incident lies not only in the number of organizations involved, but also in what may have been exposed inside their environments.”

Back to the top ↑

What is at risk?

Information that is potentially accessible to attackers includes cloud credentials, source code access, server keys, software development secrets, and “other credentials that could give attackers access to critical business systems.”

“For businesses, these credentials can be extremely sensitive because they are often what employees, applications and automated systems use to prove their identity,” warned CloudSEK. “If attackers successfully obtained them, they may not need to ‘hack’ the company again. They could simply log in using legitimate credentials.”

If valid credentials were obtained, attackers could potentially access corporate cloud environments, enter internal servers and systems, steal proprietary source code, access or manipulate software-development infrastructure, move deeper into corporate networks, use legitimate company credentials to disguise malicious activity, or target customers, partners, or suppliers through trusted access.

Meaning, the incident potentially exposed the digital keys to some of the most sensitive parts of the organizations’ technology environments.

While warning the named companies about the potential risks, CloudSEK emphasized that appearing in the dataset does not necessarily mean they were successfully breached or that data was stolen.

However, it does mean that information associated with the organization was identified in the exposure and should be investigated urgently.

This is just one of the steps that those affected—or who fear they may be—can, and should take.

Back to the top ↑

Recommendations

The United States Federal Bureau of Investigation (FBI) issued an advisory on July 2, 2026, with regard to the TeamPCP cyber group, highlighting the “continuing security concern surrounding the group and its activity.”

According to the FBI, in addition to the LiteLLM attack, TeamPCP has also modified other tools, including Trivy, KICS, and the Telnyx Python SDK—developer tools and libraries used to build, integrate, and secure software systems.

For those potentially affected by TeamPCP’s attacks, the FBI recommended several measures, including improving credential hygiene, hardening system and pipeline configurations, securing artifact integrity, governing third-party service use, enhancing logging and visibility, and monitoring for anomalous pipeline behavior.

Meanwhile, CloudSEK made its exposure research publicly available so potentially affected organizations can determine whether their infrastructure appears in the dataset and act before exposed access can be reused.

To this end, CloudSEK released a free exposure-checking tool to help organizations determine whether credentials or infrastructure associated with them appear in the identified dataset.

The firm also suggested that organizations identified in the exposure should investigate relevant systems, review access logs, and immediately rotate or revoke potentially exposed credentials.

Back to the top ↑

Beyond the immediate implications for those affected by the LiteLLM attack, the incident demonstrated how AI infrastructure and supply chain are emerging as valuable targets for cybercriminals.

“Companies are rapidly connecting AI tools to their cloud infrastructure, internal applications, source code, databases and business systems,” explained CloudSEK. “As a result, compromising an AI gateway or related software may provide attackers with access to much more than the AI application itself… This makes the AI layer an increasingly attractive point of entry for attackers.”

As well as providing a vulnerable and attractive attack vector for hackers, AI is increasingly becoming a valuable tool in the cyber-criminal arsenal.

In a blog published on May 7, the International Monetary Fund (IMF)—an international organization that works to promote global economic stability—warned that AI is amplifying cyber threats and undermining financial stability.

According to the IMF, AI is “transforming how the financial system copes with vulnerabilities and reacts to incidents,” for better and worse. It also cited analysis that suggested extreme cyber‑incident losses could trigger funding strains, raise solvency concerns, and disrupt broader markets.

“The financial system relies on shared digital infrastructure that’s highly interconnected, including software, cloud services, and networks for payments and other data,” the IMF wrote. “Advanced AI models can dramatically reduce the time and cost needed to identify and exploit vulnerabilities, raising the likelihood of simultaneously discovering and targeting weaknesses in widely used systems.”

As a result, it warned that “cyber risk is increasingly about correlated failures that could disrupt financial intermediation, payments, and confidence at the systemic level.”

This concern about systemic risk mirrors the warnings voiced by CloudSEK regarding the AI software supply chain attack and how increasingly interconnected digital systems can allow a single well-placed breach to cascade through industries.

In order for artificial intelligence (AI) to work right within the law and thrive in the face of growing challenges, it needs to integrate an enterprise blockchain system that ensures data input quality and ownership—allowing it to keep data safe while also guaranteeing the immutability of data. Check out CoinGeek’s coverage on this emerging tech to learn more why Enterprise blockchain will be the backbone of AI.

Back to the top ↑

Watch: AI is becoming a game-changer for iGaming

Advertisement
Advertisement