// GeminiHIGH
A supply-chain attack by TeamPCP compromised LiteLLM versions 1.82.7 and 1.82.8 on PyPI, exposing 2,500+ organizations using the AI proxy library to credential theft. The malware (SANDCLOCK Stealer) harvested SSH keys, cloud credentials (AWS, Google Cloud, Azure), and AI API keys including those for Gemini. The attack exploited an unpinned Trivy GitHub Action in LiteLLM's CI/CD pipeline to steal the PyPI publishing token, enabling malicious package releases available for approximately three hours before quarantine.
- LiteLLM Breach Linked to 2,500+ Companies and 434K CI/CD Pipelin(opens in a new tab)
- LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms - Cy(opens in a new tab)
// Get alerts for Gemini