Protos Labs Threat Intelligence

A poisoned AI-gateway package quietly harvested cloud, CI/CD and AI credentials from an assessed 2,500+ organisations worldwide — several of them tied to Singapore's banking, fintech, media and digital economy.
Prepared by Protos Labs Threat Intelligence · v1, 14 Aug 2026 · Audience: CISOs and security leaders, with emphasis on Singapore CII, financial-sector and software-producing organisations · Distribution: TLP:CLEAR — share freely within and between organisations.
LiteLLM, a widely deployed open-source LLM proxy gateway (at roughly 3.4 million downloads a day) shipped two malicious releases to PyPI on 24 March 2026. They were live for only about 40 minutes before removal, but the window was long enough for hundreds of thousands of automated installs.
LiteLLM itself was not attacked head-on. The compromise is assessed to have started with the hijack of Trivy, a trusted security scanner. Malicious code was force-pushed over its release tags using a leaked automation token that had been rotated but not fully revoked. That poisoned scanner then flowed into LiteLLM's unpinned build pipeline — producing the tainted 1.82.7 and 1.82.8 packages.
Release 1.82.8 shipped a .pth file that executes at Python interpreter startup, so the payload ran wherever the package was merely installed — even where no code imported LiteLLM and even where teams relied on --ignore-scripts. Because LiteLLM is a transitive dependency of frameworks such as DSPy, MLflow, CrewAI, OpenHands and Arize Phoenix, many affected parties never chose to install it. On each host the credential stealer (tracked by Google as SANDCLOCK) escalated to root and swept SSH keys, AWS/GCP/Azure credentials, Kubernetes tokens, .env secrets, and AI-provider keys including OPENAI_API_KEY and ANTHROPIC_API_KEY. Collected data was sealed and shipped to a typosquatted exfiltration domain (models.litellm[.]cloud, not affiliated with LiteLLM/BerriAI); where exfiltration failed, the malware staged the loot in a public repository created inside the victim's own GitHub account.
Later analysis expanded the timeline: the 40-minute PyPI window is assessed as the closing act of a roughly five-day collection run that began with the Trivy compromise on 19 March — approximately 95% of affected organisations show collection activity before the LiteLLM packages went live. The harvested data is already being brokered on Telegram and linked to the Vect ransomware affiliate programme. Additionally, FBI's July 2026 FLASH advisory assesses the stolen credentials are likely to be weaponised long after the intrusion.
High. Driven by credential-wide theft from build pipelines, confirmed downstream reach, and active resale linked to a ransomware affiliate — not by encryption of victim systems. The live threat is secondary compromise from reused secrets.
ConfidenceHigh (incident); High (campaign attribution to TeamPCP). Core technical claims are corroborated across CloudSEK, SOCRadar, Unit 42, Aqua Security and Mandiant. Exposure counts are reconstructed from intelligence sources and should be read as order-of-magnitude — potential exposure, not a confirmed victim census.
Attribution: the broader campaign is attributed to TeamPCP (tracked by Google Threat Intelligence Group as UNC6780; aliases PCPcat, ShellForce, DeadCatx3), a financially motivated actor whose signature is backdooring trusted developer and security tooling. LiteLLM is one confirmed stage in a sustained 2026 campaign that also touched Trivy, Checkmarx KICS, TanStack, the Telnyx SDK and others — see the related Protos Labs report, TeamPCP's Shai-Hulud Campaign & the Copycat Wave (Jun 2026).
An automated agent exploits a pull_request_target misconfiguration in Trivy's GitHub Actions and takes a privileged token. Aqua Security rotates credentials, but containment is not atomic — residual access survives.
TeamPCP force-pushes malicious Trivy release tags and publishes a poisoned build minutes later. Collection activity is first observed ~18 minutes after.
Malicious Trivy images pushed to Docker Hub, widening the collection window.
LiteLLM 1.82.7 reaches PyPI. Thirteen minutes later, 1.82.8 adds the interpreter-startup .pth payload.
PyPI quarantines both releases — roughly 40 minutes after the first went live.
CVE-2026-33634 added to CISA's Known Exploited Vulnerabilities catalogue.
FBI issues FLASH-20260702-01, warning that harvested credentials will be reused.
Exposure datasets published: an assessed 2,500+ organisations and ~434,000 CI/CD files reconstructed.
The following Singapore-linked entities are assessed to appear in the reconstructed exposure dataset.
Read as potential exposure, not confirmed compromise. The list above is derived by matching Singaporean organisations within the full dataset, and is assessed at the exposure level only. Cybersecurity teams can reach out to CloudSEK for full details of what was leaked.
Primary vendor research
CloudSEK — 2,500+ Companies and 434,000 CI/CD Pipelines Exposed (11 Aug 2026)
SOCRadar — LiteLLM Supply Chain Attack Explained (13 Aug 2026)
Hudson Rock — Largest AI Supply Chain Breach of 2026: LiteLLM Hack
Corroborating / primary statements
LiteLLM (BerriAI) incident report · Unit 42 · Aqua Security · Google Threat Intelligence Group / Mandiant · Sophos · CERT-EU
Government & standards
FBI FLASH-20260702-01 · CISA KEV (CVE-2026-33634) · NIST NVD · MITRE ATT&CK
Protos AI automates CTI investigations using agentic AI — from OSINT collection to structured analysis. Speak to our team to see it in action.