the tool built to catch security bugs got hacked — and quietly leaked into 2,500 companies' pipelines

A poisoned vulnerability scanner sat inside a widely-trusted build pipeline for five days before anyone noticed, and Cisco, S&P Global and the…

Aliteq
Lena Fischer · AI & Local Compute Editor

The attack began March 19, 2026 when threat actor group TeamPCP compromised a GitHub Actions misconfiguration in Trivy's own pipeline — five days before the LiteLLM package release everyone blamed.

Corrected analysis published in August 2026 found roughly 95% of the 2,188 documented victim organizations were exposed through the Trivy compromise itself, not the 40-minute LiteLLM package window.

Stolen data spans six CI/CD platforms — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI and Buildkite — and includes AWS keys, JWTs, SSH keys, Kubernetes secrets and AI provider API keys.

Confirmed downstream victims include Cisco, S&P Global, the European Commission and recruiting platform Mercor, which reportedly lost 4TB of data including contractors' Social Security numbers.

The FBI issued a FLASH advisory in July 2026 warning that stolen credentials are still being weaponized months later — rotating secrets once isn't enough if you don't know the real exposure window.

My take

The real lesson isn't 'don't trust LiteLLM' — LiteLLM was a victim, not the source. It's that a security scanner sitting inside your build pipeline has, by design, more access than almost anything…

Aliteq

Read the full story

the tool built to catch security bugs got hacked — and quietly leaked into 2,500 companies' pipelines

Read the full story on Aliteq