SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies 

Today, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.  

What’s different from general coverage:

  • They worked from the ranked company list. SOCRadar analyzed the 2,188 organization records at row level and the timeline changes.
  • The 40-minute PyPI window was the end of a 5-day collection run, not the start. 95% of affected organizations were already exposed before March 24, and the earliest record lands 18 minutes after the poisoned Trivy build published on March 19.

SOCRadar Findings/Differentiators:

  • Six CI/CD platforms, GitHub Actions and GitLab CI near-equal, self-hosted GitLab included
  • Footprint skews European and Latin American, Germany then Brazil then France, 137 TLDs, eight .gov
  • Credentials reach npm and Docker publishing tokens, Stripe, Twilio, SendGrid, not just AI keys
  • Our Dark Web monitoring caught the loot brokered on Telegram at 150+ GB, tied to Vect ransomware

SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading