153GB of stolen credentials surface five months after LiteLLM supply chain attack
Cybersecurity firms Hudson Rock and CloudSEK say a March 2026 supply-chain attack tied to LiteLLM exposed about 2,500 organizations. A 153GB archive linked to the TeamPCP campaign contained 433,909 files and 118,829 CI runner dumps. LiteLLM versions 1.82.7 and 1.82.8 were live briefly before PyPI quarantined them, but stolen credentials may remain valid until rotated, according to the reports.
How this was made

The 30-second read
Why it matters
The newest concrete element is the surfaced 153GB archive and the expanded, attributed exposure counts (2,500 organizations, ~434,000 pipelines) plus a high-confidence list of named enterprises. The trading relevance is mainly second-order: potential incident response, credential rotation costs, and any later disclosures.
Market read
This is a follow-on disclosure of credential exposure scale from a widely used developer dependency, but it does not provide confirmed, company-specific breach outcomes or financial metrics.
What to watch
Market impact may be driven more by any subsequent company disclosures, regulatory actions, or confirmed breach costs than by the reconstructed exposure dataset itself.
Background
A March 2026 supply-chain attack compromised Trivy used in LiteLLM’s CI pipeline, leading to malicious LiteLLM PyPI releases that harvested credentials.
Ticker impact
CloudSEK’s high-confidence exposure list for the LiteLLM supply-chain credential theft includes NVIDIA, implying potential secret harvesting risk.
Limited direct near-term impact unless the company discloses an incident, remediation costs, or operational disruption.
The article provides exposure attribution, not confirmed compromise or financial impact, and does not report any NVIDIA-specific breach confirmation or remediation timeline.
CloudSEK’s high-confidence list of potentially exposed organizations includes Amazon Web Services, tied to stolen CI/CD secrets from the LiteLLM attack.
No clear directional move expected from this report alone; impact would depend on any disclosed customer/ops disruption.
The text is about reconstructed exposure and does not establish confirmed compromise, customer impact, or AWS-specific operational effects.
CloudSEK’s high-confidence list includes Cisco Systems as potentially exposed to credential theft tied to the LiteLLM malicious PyPI packages.
Near-term price impact is unlikely absent Cisco confirmation of compromise or material remediation.
The report is exposure-focused and does not quantify confirmed breach scope or financial consequences for Cisco.
CloudSEK’s high-confidence exposure list includes Salesforce, tied to stolen CI/CD secrets from the LiteLLM supply-chain attack.
No strong directional signal without Salesforce disclosure of confirmed compromise or customer impact.
The article provides a reconstructed exposure list, not confirmed compromise, and includes no Salesforce-specific incident details.
CloudSEK’s high-confidence exposure list includes ServiceNow, associated with stolen credentials from the LiteLLM malicious package releases.
Market reaction would likely be muted unless ServiceNow reports confirmed compromise or material remediation.
The text does not confirm ServiceNow compromise or provide any financial/operational impact metrics.
CloudSEK’s high-confidence exposure list includes S&P Global, tied to credential theft from the LiteLLM supply-chain attack.
No clear immediate trading signal without confirmed compromise or disclosed incident impact.
The report is exposure attribution and does not provide confirmed breach evidence or financial impact for S&P Global.
CloudSEK’s high-confidence exposure list includes FedEx, tied to stolen CI/CD secrets from the LiteLLM malicious package releases.
Limited near-term impact absent FedEx confirmation of compromise or material remediation.
The article provides exposure lists and recommended actions, not confirmed incident impact for FedEx.
CloudSEK’s high-confidence exposure list includes Zscaler, tied to stolen CI/CD secrets from the LiteLLM supply-chain attack.
Potentially modest negative sentiment if Zscaler confirms compromise, but no confirmed incident is provided here.
The report is exposure-focused and does not state confirmed compromise or quantify impact for Zscaler.
Market effects
Highlights systemic risk in developer tooling and CI/CD supply chains, reinforcing demand for secret rotation, pipeline hardening, and SBOM-style controls.
Global exposure list spans US and non-US firms, but the article does not report region-specific incidents.
Named organizations across multiple industries suggest broad enterprise remediation activity, though financial impact is not quantified.
Counterpoint
Exposure lists do not equal confirmed compromise; many named firms may have had no usable secrets harvested or may already have rotated credentials.
Key entities
- software_dependencyLiteLLM
Python gateway package whose CI pipeline installed a compromised Trivy version and shipped malicious credential-stealing releases (1.82.7, 1.82.8).
- threat_intelligence_firmCloudSEK
Confirmed the fallout report published Aug 11, 2026 and provided a high-confidence list of potentially exposed organizations.
- cybersecurity_firmHudson Rock
Obtained and analyzed the 153GB exfiltration archive, attributing CI runner dumps to corporate domains.
- US_regulatorCISA
Added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog with CVSS 9.3.
- threat_actorTeamPCP
Threat actor attributed to publishing the malicious PyPI packages after obtaining PyPI credentials.




