{"id":1155106,"date":"2026-08-18T06:30:24","date_gmt":"2026-08-18T06:30:24","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/1155106\/"},"modified":"2026-08-18T06:30:24","modified_gmt":"2026-08-18T06:30:24","slug":"litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/1155106\/","title":{"rendered":"LiteLLM Supply-Chain Attack &#8211; Technology, Banking and Healthcare the Most Affected"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tLiteLLM Supply-Chain Attack \u2013 Technology, Banking and Healthcare the Most Affected\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> August 17, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/08\/signal-2026-08-17-18-48-09-671.jpg\" alt=\"\"\/><\/p>\n<p>The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Resecurity (USA)<\/strong> <a href=\"https:\/\/www.resecurity.com\/blog\/article\/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action\" rel=\"nofollow noopener\" target=\"_blank\">estimated<\/a> the most affected sectors by the <strong>\u201c<a href=\"https:\/\/securityaffairs.com\/194741\/cyber-crime\/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html\" data-type=\"post\" data-id=\"194741\" rel=\"nofollow noopener\" target=\"_blank\">SANDCLOCK<\/a>\u201d backdoor<\/strong>, which was planted as a result of the code repository compromise. According to cybersecurity experts, <strong><a href=\"https:\/\/securityaffairs.com\/tag\/litellm\" data-type=\"post_tag\" data-id=\"16714\" rel=\"nofollow noopener\" target=\"_blank\">LiteLLM <\/a>\/ <a href=\"https:\/\/securityaffairs.com\/tag\/teampcp\" data-type=\"post_tag\" data-id=\"16716\" rel=\"nofollow noopener\" target=\"_blank\">TeamPCP<\/a> Supply-Chain Attack<\/strong> will have long-lasting consequences.<\/p>\n<p class=\"wp-block-paragraph\">By compromising a well-known component in AI applications, adversaries will multiply the blast radius\u2014some of the victim organizations are still unaware of the backdoor and its impact. LiteLLM is a popular <strong>open-soure AI gateway<\/strong> and utility library that unifies API calls for over 100 large language model providers, such as <strong>OpenAI, Anthropic, Google Gemini,<\/strong> and local <strong>Ollama models<\/strong>.<\/p>\n<p class=\"wp-block-paragraph\">Such incidents involve substantial MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond). The threat actor group \u201c<a href=\"https:\/\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-79.png\" data-type=\"attachment\" data-id=\"189953\" rel=\"nofollow noopener\" target=\"_blank\">TeamPCP<\/a>\u201d compromised maintainer credentials for LiteLLM and published malicious package versions 1.82.7 and 1.82.8 to PyPI around March 2026 \u2013 creating a window of exposure lasting at least a few months.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Over 2,500+ organizations<\/strong> and hundreds of thousands of CI\/CD environments suffered full-credential exposure, compromising cloud infrastructure keys, repository access tokens, SSH credentials, Kubernetes secrets, and AI provider API keys (such as OpenAI and Anthropic).<\/p>\n<p class=\"wp-block-paragraph\">Resecurity has acquired the <strong>150GB archive<\/strong> attributed to the LiteLLM supply-chain attack conducted by TeamPCP using the \u201cSANDCLOCK\u201d credential-stealer. Per published incident reporting \u2014 accompanying victim manifests enumerate 898 compromised GitHub owners (organisations\/accounts) across 2,038 repositories. The affected owners include major global enterprises \u2014 among them Microsoft, Azure, IBM, NVIDIA, PayPal (Zettle), Deloitte, Bosch, S&amp;P Global, Elevance Health, 84.51\u00b0 (Kroger), Adeo (Leroy Merlin), K\u00e4rcher, Dr\u00e4ger, ID.me and 1inch.<\/p>\n<p class=\"wp-block-paragraph\">Top 10 the most impacted sectors (by victim organization profile):<\/p>\n<ul class=\"wp-block-list\">\n<li>Technology \/ Software<\/li>\n<li>Banking \/ Finance \/ Insurance<\/li>\n<li>Healthcare \/ Pharma \/ Medtech<\/li>\n<li>Retail \/ E-Commerce<\/li>\n<li>Media \/ Gaming \/ Adtech<\/li>\n<li>Manufacturing \/ Industrial<\/li>\n<li>Professional Services<\/li>\n<li>Cybersecurity<\/li>\n<li>Crypto<\/li>\n<li>Government<\/li>\n<\/ul>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/08\/Resecurity_LiteLLM_AffectedEntities_by_Sector_1.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"783\" height=\"1024\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/08\/Resecurity_LiteLLM_AffectedEntities_by_Sector_1.png\" alt=\"Resecurity LiteLLM AffectedEntities by Sector_1\" class=\"wp-image-197379\" style=\"width:635px;height:auto\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Resecurity enumerated 2,146 records by key name (values never inspected beyond structural masking). The composition is overwhelmingly GitHub CI-CD identity material, with a long tail of high-value cloud and registry credentials.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/08\/Resecurity-LiteLLM-2.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" width=\"665\" height=\"152\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/08\/Resecurity-LiteLLM-2.png\" alt=\"Resecurity LiteLLM\" class=\"wp-image-197382\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Victim manifests (owners.txt, repos.txt) enumerate 898 distinct compromised GitHub owners across 2,038 repositories. The distribution is long-tailed: 631 owners have a single affected repo, while the most-affected owner (Cencosud-Cencommerce) has 64. Critically, the owner list includes major global enterprises and regulated organisations.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/08\/Resecurity-LiteLLM-3.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" width=\"665\" height=\"204\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2026\/08\/Resecurity-LiteLLM-3.png\" alt=\"Resecurity LiteLLM\" class=\"wp-image-197381\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Every organization affected by the LiteLLM incident should revoke or rotate GitHub App private keys, PATs, AWS\/GCP\/Firebase credentials, ECR\/JFrog tokens, SSH keys, and signing passwords, and invalidate sessions.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Follow me on Twitter:\u00a0<\/strong><a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>@securityaffairs<\/strong><\/a><strong>\u00a0and\u00a0<\/strong><a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Facebook<\/strong><\/a><strong>\u00a0and\u00a0<\/strong><a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Mastodon<\/strong><\/a><strong\/><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Pierluigi\u00a0Paganini<\/strong><\/a><strong\/><\/p>\n<p class=\"wp-block-paragraph\"><strong>(<\/strong><a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\"><strong>SecurityAffairs<\/strong><\/a><strong>\u00a0\u2013\u00a0hacking,\u00a0newsletter)<\/strong><strong\/><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"LiteLLM Supply-Chain Attack \u2013 Technology, Banking and Healthcare the Most Affected Pierluigi Paganini August 17, 2026 The SANDCLOCK&hellip;\n","protected":false},"author":2,"featured_media":1155107,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[4316],"tags":[13509,15986,211228,105,4348,61459,211229,314156,13510,211230,314157,211231,211232,314158,314159,16,15],"class_list":["post-1155106","post","type-post","status-publish","format-standard","has-post-thumbnail","category-healthcare","tag-cybercrime","tag-hacking","tag-hacking-news","tag-health","tag-healthcare","tag-information-security-news","tag-it-information-security","tag-litellm","tag-malware","tag-pierluigi-paganini","tag-sandclock-backdoor","tag-security-affairs","tag-security-news","tag-supply-chain-attack","tag-teampcp","tag-uk","tag-united-kingdom"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1155106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=1155106"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1155106\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/1155107"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=1155106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=1155106"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=1155106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}