- Sources: report, discussion
- Summary: This archive covered the March 2026 LiteLLM supply chain compromise on 2026-08-12 from CloudSEK's victim list, carrying the same figures of about 434,000 CI/CD pipelines and a 40-minute publication window, and recording that no affected version range was established. Ars Technica, dated 2026-08-12 and updated 2026-08-13, adds three things that entry lacked: it names the compromised builds as LiteLLM 1.82.7 and 1.82.8, it puts the harvested material at a 195TB file held by Hudson Rock, and it describes the packages as reading the memory of infected machines and exfiltrating the contents through an attacker-controlled channel, covering cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables and AI provider keys. An update at the foot of the piece has researcher Kevin Beaumont reporting that one affected organization told him it had rotated every credential, and that when he tested that organization's leaked credentials almost every one still worked. The status stays developing rather than moving to confirmed, because the affected-version claim traces to CloudSEK and Hudson Rock rather than to a maintainer advisory, this step found no GitHub Security Advisory from BerriAI/litellm for those builds, and both research posts returned 404 at the URLs tried.
- Why it matters: Memory scraping is broader than environment-variable collection, so exposure on a machine that installed 1.82.7 or 1.82.8 is not bounded by what sat in the environment block. Beaumont's re-test covers one organization and is a reason to verify a rotation reported as complete, not a measurement of the leaked set as a whole.
- Follow-up: Track a maintainer or vendor advisory naming the compromised builds, and a reachable primary from CloudSEK or Hudson Rock.
send feedback on this story