Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

LiteLLM Supply Chain Attack: A Global Threat to Technology, Banking, and Healthcare




The SANDCLOCK LiteLLM supply-chain attack has exposed credentials of over 2,038 repositories, affecting technology, finance, healthcare, retail, and more. The attack, attributed to the malicious group "TeamPCP," compromised maintainer credentials for LiteLLM, a popular open-source AI gateway and utility library, and published malicious package versions 1.82.7 and 1.82.8 on PyPI. The affected sectors include technology, banking, healthcare, retail, media, gaming, adtech, manufacturing, industrial, professional services, cybersecurity, and crypto. Organizations are advised to take immediate action to secure their cloud infrastructure, repository access tokens, SSH credentials, Kubernetes secrets, and AI provider API keys.



  • Over 2,038 repositories were affected in the SANDCLOCK LiteLLM supply-chain attack.
  • Credentials of over 898 compromised GitHub owners across 2,038 repositories were exposed.
  • Major global enterprises and regulated organizations, such as Microsoft and PayPal, were compromised.
  • Organizations are advised to revoke or rotate credentials, invalidate sessions, and secure their supply chains.
  • The attack highlighted the need for vigilance and proactive security measures to prevent similar attacks in the future.



  • The recent SANDCLOCK LiteLLM supply-chain attack has sent shockwaves across the globe, exposing credentials of over 2,038 repositories and affecting technology, finance, healthcare, retail, and more. The attack, attributed to the malicious group "TeamPCP," compromised maintainer credentials for LiteLLM, a popular open-source AI gateway and utility library, and published malicious package versions 1.82.7 and 1.82.8 on PyPI.

    The consequences of this attack will be long-lasting, as it not only exposed credentials but also multiplied the blast radius, with some organizations still unaware of the backdoor and its impact. The affected sectors include technology, banking, healthcare, retail, media, gaming, adtech, manufacturing, industrial, professional services, cybersecurity, and crypto. Major global enterprises and regulated organizations, such as Microsoft, Azure, IBM, NVIDIA, PayPal, Deloitte, Bosch, S&P Global, Elevance Health, 84.51° (Kroger), Adeo (Leroy Merlin), Kärcher, Dräger, ID.me, and 1inch, have been compromised.

    The attack involved substantial Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), highlighting the need for organizations to be vigilant and proactive in securing their cloud infrastructure, repository access tokens, SSH credentials, Kubernetes secrets, and AI provider API keys. The compromised credentials include cloud infrastructure keys, repository access tokens, SSH credentials, Kubernetes secrets, and AI provider API keys, such as OpenAI and Anthropic.

    Resecurity, a cybersecurity firm, acquired the 150GB archive attributed to the LiteLLM supply-chain attack conducted by TeamPCP using the "SANDCLOCK" credential-stealer. The incident reporting enumerated 898 compromised GitHub owners across 2,038 repositories, including major global enterprises and regulated organizations. The distribution of affected owners is long-tailed, with 631 owners having a single affected repo, while the most-affected owner, Cencosud-Cencommerce, has 64.

    To mitigate the impact of this attack, organizations are advised to revoke or rotate GitHub App private keys, PATs, AWS/GCP/Firebase credentials, ECR/JFrog tokens, SSH keys, and signing passwords, and invalidate sessions. This article serves as a warning to the tech industry and organizations worldwide to be vigilant in securing their supply chains and protecting their sensitive data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/LiteLLM-Supply-Chain-Attack-A-Global-Threat-to-Technology-Banking-and-Healthcare-ehn.shtml

  • https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html


  • Published: Mon Aug 17 13:17:38 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us