Summary
A massive supply-chain attack on LiteLLM has led to the harvesting of credentials from over 2,500 organizations, including major companies like Cisco, Samsung, and AWS. The breach, which occurred in March 2026, exploited a vulnerability in Aqua Security's Trivy, and some compromised credentials remain active nearly five months later.