Published Security3 min read
A poisoned Trivy build in March is why 2,488 companies now have CI secrets in a 153GB dump
Hudson Rock says it holds 433,909 files harvested from build runners after a compromised Trivy release handed attackers LiteLLM's publishing tokens. Notification is not coming for everyone.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco and Salesforce.
- Hudson Rock says it obtained and analysed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains.
- The LiteLLM breach had its roots in an earlier compromise of Trivy, a popular open-source vulnerability scanner. LiteLLM itself is an open-source proxy gateway developers use to route requests to different AI models.
- On March 19, 2026, TeamPCP, a cybercriminal group that emerged in late 2025, used stolen credentials to publish a compromised version of Trivy.
- LiteLLM's build pipeline installed Trivy automatically, giving the poisoned scanner read access to the runner environment and allowing the attackers to steal the project's PyPI publishing tokens.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Hudson Rock says it has obtained and analysed the 153GB archive stolen in the LiteLLM supply chain attack: 433,909 files, with 118,829 CI runner dumps attributed to 2,488 corporate domains [2]. What matters for anyone reading this is where the compromise actually started, which was one layer upstream of LiteLLM, in a poisoned build of the open-source vulnerability scanner Trivy [5].
The sequence is short. On March 19, 2026, TeamPCP, a cybercriminal group that emerged in late 2025, used stolen credentials to publish a compromised version of Trivy [6]. LiteLLM's build pipeline installed Trivy automatically, which gave the poisoned scanner read access to the runner environment and let the attackers take the project's PyPI publishing tokens [7]. Five days later [22] they used those tokens to push two malicious LiteLLM releases, 1.82.7 and 1.82.8, to the Python Package Index [8]. Hudson Rock CTO Alon Gal says a window of roughly 40 minutes in which the LiteLLM dependency was compromised produced over 430,000 instances of secret harvesting [9].
The haul is what you would expect from reading environment variables at build time. Screenshots published with the research show AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables and AI provider API keys captured during pipeline execution [11]. Hudson Rock says the data links to organisations including NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte and Siemens [10], and separately to AWS, Samsung, Cisco and Salesforce domains [1]. CloudSEK, working from a separate dataset of about 434,000 stolen files, counted close to 2,500 exposed organisations and stressed that its figures reflect exposure rather than confirmed breaches [12]. The two counts are effectively the same population [24]. Security researcher Kevin Beaumont says he has confirmed the data is legitimate with multiple victim organisations and describes a significant volume of sensitive content [13].
Waiting to be told you are in it is the wrong posture, for two reasons. First, attribution is hard: Hudson Rock says accurate identification requires hard infrastructure markers rather than simple committer emails, and cites a leaked pipeline whose committer email pointed at SiriusXM while a self-hosted GitLab instance at gitlab.adswizz.com pointed at the subsidiary AdsWizz [14][15][16]. Second, a large share of the dumped files have no obvious owner at all: database passwords, third-party API keys and cloud credentials with no company email, custom domain or internal server name to trace [17]. Organisations can therefore be exposed in this dataset without ever being identified as affected [18].
Hudson Rock's guidance is to audit for LiteLLM 1.82.7 and 1.82.8 and treat any secret reachable from the LiteLLM environment as compromised, with the advice aimed at users of AI proxy infrastructure, third-party CI/CD vulnerability scanners and downstream AI packages [19]. It also recommends rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity back to March 24, and checking for unauthorised .pth files and suspicious systemd services [20]. The firm says the archive is not leaked anywhere at present and is not circulating widely, which is the only reason rotation is still ahead of exploitation [21].
The unanswered question is the size of the upstream blast radius. The reporting names LiteLLM as the downstream victim of the poisoned Trivy build but does not say how many other build pipelines installed the same scanner in that window [25]. Any pipeline that pulled Trivy on or after March 19 was, mechanically, in the same position LiteLLM was.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco and Salesforce.
- [2]
Hudson Rock says it obtained and analysed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains.
- [5]
The LiteLLM breach had its roots in an earlier compromise of Trivy, a popular open-source vulnerability scanner. LiteLLM itself is an open-source proxy gateway developers use to route requests to different AI models.
- [6]
On March 19, 2026, TeamPCP, a cybercriminal group that emerged in late 2025, used stolen credentials to publish a compromised version of Trivy.
- [7]
LiteLLM's build pipeline installed Trivy automatically, giving the poisoned scanner read access to the runner environment and allowing the attackers to steal the project's PyPI publishing tokens.
- [8]
Using the stolen tokens, TeamPCP published two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, to the Python Package Index on March 24.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comSinisa MarkovicAug 13153GB of stolen credentials surface after LiteLLM supply chain attack
Additional citations
- Help Net Security
- Hudson Rock via Help Net Security
- Alon Gal, Hudson Rock, to Help Net Security
- CloudSEK via Help Net Security
- Kevin Beaumont, quoted by Help Net Security



