• Sources: primary, discussion
  • Summary: CloudSEK describes the March 2026 LiteLLM supply chain compromise as running through an unpinned scanner invoked in a CI job and a Python .pth file that executes at interpreter startup, inside a publication window it puts at 40 minutes. CloudSEK states the figures of 2,500 organizations and 434,000 CI/CD pipelines come from a reconstructed exposure dataset and are not proof that any listed organization was compromised. The post also carries an exposure checker that collects contact details, so the numbers are recorded here as CloudSEK's own. The compromised package versions and their publication timestamps are not established here, because the CloudSEK post as read for this digest names no affected version range, so a reader cannot determine exposure from a pinned version alone and has to check whether the CI job resolved an unpinned dependency inside the 40-minute window.
  • Why it matters: Execution at interpreter startup through a .pth file means --ignore-scripts did not help, and credentials reachable in that window stay valid unless rotated.
  • Follow-up: Independent confirmation of the exposure dataset, and any statement from the LiteLLM maintainers.

send feedback on this story