Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations
Blog post from GitGuardian
A March 2026 LiteLLM PyPI supply-chain compromise that remained active for roughly 40 minutes reportedly produced a 153GB archive containing 433,909 files, including 118,829 CI runner dumps attributed by Hudson Rock to 2,488 corporate domains, while CloudSEK independently investigated the same campaign. The root-level payload collected SSH keys, cloud and Kubernetes credentials, CI/CD secrets, environment files, Docker data, cryptocurrency wallets, and AI-provider keys, potentially granting access to broader infrastructure and model environments. Researchers found examples of exposed deployment tokens, API keys, JWTs, and NPM tokens, raising the possibility that stolen publishing credentials could enable additional supply-chain attacks. Many records cannot be linked to an organization because they lack identifying emails, domains, or hostnames, and even attributed data can misdirect disclosures when infrastructure belongs to subsidiaries or related companies. The account emphasizes that organizations should rely on internal credential inventories, endpoint and continuous secrets monitoring, automated credential validation and rotation, and honeytokens to identify exposure or unauthorized use when external notification is not possible.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 2,244 | 480 | 132 | -13% |
| Kubernetes | 1 | 3,490 | 385 | 112 | +26% |
| LLM | 1 | 5,068 | 1,020 | 229 | -34% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.