LiteLLM/Trivy Supply-Chain Campaign Linked to Breaches at Six High-Profile Organizations

· Original article ↗

Summary

Hudson Rock describes six organizations affected by the LiteLLM/Trivy supply-chain campaign, alleging exposed CI/CD credentials enabled access to cloud, code, and other systems. Reported impacts range from stolen data to malicious Telnyx SDK releases.

Key points

  • Hudson Rock says it disclosed exposed CI/CD pipelines, cloud keys, and API tokens to more than 250 organizations, including over 30 Fortune 500 companies.
  • The report links exposed AWS credentials and other secrets in CI runner data to alleged access at Guesty and S&P Global; extortion groups claim large volumes of data were stolen.
  • Cisco source code theft is linked to a compromised development environment running a poisoned Trivy container, with GitHub and other credentials reportedly exposed.
  • The European Commission confirmed an incident affecting europa.eu AWS infrastructure; the article says AWS credentials and GitLab tokens were exposed.
  • Mercor reported being affected by the LiteLLM supply-chain attack. The article describes reported theft of data including source code and contractor records.
  • Malicious Telnyx Python SDK versions 4.87.1 and 4.87.2 were published to PyPI on March 27, 2026. Telnyx said its platform, APIs, customer data, and voice and messaging infrastructure were not compromised.

Article Details

Victim Organization
Guesty; S&P Global; Cisco; European Commission; Mercor; Telnyx
Incident Type
Supply-chain compromise involving LiteLLM and Trivy, followed by alleged or reported unauthorized access to victim CI/CD and cloud environments, data theft, and downstream extortion. Telnyx also confirmed malicious Python SDK versions were published.
Data Types Exposed
  • Internal projects and source code
  • Emails and attachments
  • Userbase and user database records
  • Cloud credentials, API keys, tokens, and secrets
  • Core architectural secrets
  • Potential AI training methodologies
  • Video interviews
  • Social Security numbers and biometric data
Affected Records
Vect ransomware reportedly claimed Guesty's data included 4 million sent and received emails with attachments. Reports cited more than 40,000 Mercor contractors whose records contained Social Security numbers and biometric data.
Affected Data Size
Vect ransomware reportedly claimed 700 GB of Guesty data and 250 GB of S&P Global data were exfiltrated. Available reports attributed approximately 4 TB of extracted data to the Mercor incident, including 939 GB of proprietary source code.
Operational Impact
The article reports or assesses access to victim CI/CD pipelines, cloud environments, repositories, and internal infrastructure. Mercor reportedly suffered lateral movement and data extraction; Meta subsequently paused a major data contract. Telnyx confirmed its PyPI distribution channel was compromised, but said its platform, APIs, customer data, and voice/messaging infrastructure were not compromised.
Ransom Or Extortion
The article says Guesty and S&P Global were listed on the Vect ransomware group's leak site and attributes data-volume claims to that group. It describes the harvested credentials as fueling downstream extortion. Lapsus$ claimed to have permanently sold Mercor data to Chinese enterprises. These actor statements and leak-site listings are claims, not independent confirmation of the claimed theft or sale.
Claim Status
confirmed

Threat Actors

Products

AWSthat threat actors likely gained access to critical cloud infrastructure, specifically exposing dozens of AWS Access Keys and secrets directly from Guesty’s CI pipelines.ConjurThe exposure of an Artifactory token likely allowed access to internal packages, while a Conjur API key appears to have provided a foothold into Cisco’s broader secret management infrastructure.DagsterThis would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.DatadogThis would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.DockerHow Hackers Likely Got In: According to the data dumps, it is assessed that attackers likely recovered Docker configuration files containing base64-encoded basic authentication credentials and GitHub PATs.GitHubof exposed data is staggering: judging by the telemetry, attackers likely accessed thousands of secrets, GitHub tokens, JWTs, and RSA private keys, fundamentally compromising their internal repository and cloudGitLabFurthermore, a hardcoded SSH private key and GitLab CI tokens appear to have been exposed, which would likely allow the threat actors to pivot laterally across the European Commission’s GitLab infrastructure.JFrog ArtifactoryThe exposure of an Artifactory token likely allowed access to internal packages, while a Conjur API key appears to have provided a foothold into Cisco’s broader secret management infrastructure.JiraExfiltrated environment configuration from Cisco revealing highly sensitive Conjur, GitHub, and JIRA secrets.KubernetesCompromised CI runner dumps for Guesty.com revealing exposed AWS and Kubernetes secrets.LinearThis would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.LiteLLMFrom CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy AttackPyPIOutcome of the Breach: On March 27, 2026, two unauthorized versions of the Telnyx Python SDK (4.87.1 and 4.87.2) were published to PyPI containing malicious credential-stealing code.TerraformHow Hackers Likely Got In: Evidence suggests threat actors likely intercepted temporary AWS STS session tokens and long-lived AWS keys during a terraform-actions workflow.TrivyFrom CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack

Industries

Related Articles