LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms
Two threat-intel firms report expanded victim data from a March 2026 LiteLLM supply-chain attack. CloudSEK estimates 2,500+ organisations and about 434,000 CI/CD pipelines exposed, while Hudson Rock attributes 118,829 CI runner dumps to 2,488 corporate domains. Backdoored LiteLLM 1.82.7/1.82.8 were published on PyPI for ~40 minutes via a compromised Trivy release process. Reported payload SANDCLOCK stole cloud, CI/CD and AI API credentials.
How this was made

The 30-second read
Why it matters
The article reports expanded victim data: hundreds of thousands of CI/CD-related records and thousands of corporate domains, plus details on credential theft methods and the possibility of months-long undetected exposure via public GitHub releases.
Market read
Traders should treat this as a security risk and remediation catalyst for named tech and cloud-adjacent firms, but the article does not confirm actual compromise for each victim.
What to watch
Market impact depends on whether any company issues a confirmed incident response, whether credentials were actually valid post-rotation, and whether regulators or major customers demand attestations.
Background
LiteLLM supply-chain poisoning occurred via backdoored PyPI packages (1.82.7 and 1.82.8) linked to TeamPCP, with no direct LiteLLM vulnerability and a CI cascade through an unpinned Trivy release process.
Ticker impact
CloudSEK’s high-confidence affected list includes NVIDIA, implying its CI/CD secrets may have been exposed via the LiteLLM backdoored PyPI packages.
Near-term stock impact is unlikely to be directly quantifiable from this article alone, but reputational and operational risk could pressure sentiment if confirmed publicly.
The article is threat-intel reporting and does not provide confirmed compromise, only reconstructed exposure counts and a list of potentially exposed domains.
CloudSEK’s list of potentially exposed organisations includes Amazon Web Services, indicating possible exposure of AWS CI/CD runner credentials.
No immediate, direct price signal is implied, but any escalation or confirmation could weigh on sentiment.
The piece does not disclose a specific AWS incident outcome, only that AWS is named among potentially exposed domains.
Salesforce appears in CloudSEK’s high-confidence affected list, suggesting its CI/CD pipelines may have pulled backdoored LiteLLM packages.
Material market impact would require confirmation of actual compromise and scope, which the article does not provide.
Attribution is uncertain and the article explicitly frames counts as reconstructed exposure, not proof of compromise.
ServiceNow is named in CloudSEK’s affected list, implying potential exposure of its CI/CD secrets through the LiteLLM supply-chain poisoning.
Likely limited immediate impact unless ServiceNow confirms confirmed compromise or incident response details.
The article provides threat-intel victim data and a list of potentially exposed domains, not confirmed breach confirmation.
Cisco Systems is included in CloudSEK’s high-confidence list, indicating possible exposure of CI/CD credentials via the poisoned LiteLLM releases.
No direct, article-driven price catalyst is established without confirmation of actual credential misuse.
The article does not provide evidence of Cisco-specific credential validity or confirmed compromise, only potential exposure.
Roku is named in CloudSEK’s affected list, implying its CI/CD environments may have been exposed to backdoored LiteLLM packages.
Any market reaction would depend on Roku’s confirmation and scope, which are not provided here.
The article frames exposure as reconstructed and does not confirm Roku’s actual compromise.
Market effects
Reinforces supply-chain and CI/CD security risk premium for software infrastructure, DevOps tooling, and cloud security vendors.
Primarily US-listed tech and cloud-adjacent firms are named, but the exposure is global across corporate domains.
Highlights systemic risk in open-source build pipelines and credential handling practices, likely prompting broader industry remediation.
Counterpoint
Because the article emphasizes reconstructed exposure rather than confirmed compromise, many named companies may have had no usable credentials or successfully mitigated before payload execution.
Key entities
- softwareLiteLLM
Open-source LLM gateway/library whose PyPI releases were backdoored and used in CI/CD pipelines.
- threat_actorTeamPCP
Threat group attributed to backdoored LiteLLM packages and the supply-chain poisoning cascade.
- security_firmCloudSEK
Threat intelligence firm counting 2,500+ organizations and ~434,000 CI/CD pipelines potentially exposed.
- security_firmHudson Rock
Threat intelligence firm obtaining an exfiltration archive and attributing ~118,829 CI runner dumps to 2,488 corporate domains.
- malwareSANDCLOCK
Payload name used to steal credentials and secrets from compromised CI runners.




