CTIPilot

LiteLLM

product · product:litellm single-source

Coverage timeline
3
first 2026-08-06 → last 2026-08-15
Peak priority
notable
3 notable
Sources cited
9
9 hosts
Sections touched
2
active-threats, research
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
8
pinned v19.2 · see below

ATT&CK techniques

8 techniques observed across 3 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×1

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-06/litellm-callback-hook-post-inference-tool-call-forgery · ATT&CK page ↗

Collection TA0009

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-06/litellm-callback-hook-post-inference-tool-call-forgery · ATT&CK page ↗

Impact TA0040

T1565.002Data Manipulation: Transmitted Data Manipulation×1

Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making.

Evidence: 2026-08-06/litellm-callback-hook-post-inference-tool-call-forgery · ATT&CK page ↗

Story timeline

  1. 2026-08-15The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
    active-threatsSOCRadar's row-level re-analysis moves the blast radius upstream to a compromised security scanner, which changes what a CI/CD estate has to audit
  2. 2026-08-08Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
    researchThe AI toolchain became a cloud attack surface with its own recurring vulnerability cadence, and the credentials it holds are non-human
  3. 2026-08-06LiteLLM callback hooks let an attacker who already holds gateway admin forge tool calls after inference, downstream of every prompt-level defence
    researchThe AI gateway's own extension points become the tamper surface, and reverting the config removes the evidence

Where this entity is cited

  • research2
  • active-threats1

Source distribution

  • aquasec.com1 (11%)
  • cert.europa.eu1 (11%)
  • docker.com1 (11%)
  • docs.litellm.ai1 (11%)
  • embracethered.com1 (11%)
  • labs.cloudsecurityalliance.org1 (11%)
  • securityweek.com1 (11%)
  • socradar.io1 (11%)
  • other1 (11%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about LiteLLM (3)

2026-08-15 · view entry permalink →

NOTABLENATOB1

The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned

The widely reported figure (more than 2,500 organisations compromised through poisoned LiteLLM packages) turns out to describe the wrong artifact for almost all of them. SOCRadar re-analysed the exposure dataset row by row and found that "For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry" (SecurityWeek, 2026-08-14 · SOCRadar, 2026-08-13). Collection that stops before the malicious packages exist cannot have come from them. SOCRadar times the start against the upstream event instead: the earliest collection record sits eighteen minutes after the poisoned Trivy build published, activity surged while malicious Trivy images were live on Docker Hub, and it closed once the registry quarantined the LiteLLM packages (SecurityWeek, 2026-08-14).

The upstream compromise is documented by the vendor itself. Aqua Security's incident advisory records that on 19 March "The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits", publishing a malicious Trivy build at the same time (Aqua Security, 2026-04-01). LiteLLM's own maintainers state the connection plainly: "We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow" (LiteLLM, 2026-03-24). A security scanner is an unusually good place to put credential-stealing code, because it is a tool organisations deliberately run inside their build systems with access to the material they are scanning.

One detail from Aqua's write-up deserves to outlive this incident. The poisoned tags carried GitHub's "Immutable" badge: "The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the 'Immutable' indicator. Pinning to full commit SHAs remains the only truly immutable protection" (Aqua Security, 2026-04-01). A control that displayed as satisfied while being subverted is worse than an absent one, because it ends the review.

What the correction is worth to this constituency is visible in one of the confirmed victims. CERT-EU assesses "with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP", in an intrusion into a European Commission cloud account from which "A significant volume of data (about 91.7 GB compressed) was exfiltrated ... including personal data such as names, email addresses, and email content" (CERT-EU, 2026-04-02). That is an EU institution reached through a build-pipeline dependency, not through a package a developer chose to install.

Triage: a security scanner reaching out during a build is normal behaviour, so egress from the runner is not by itself the discriminator. What separates this from a healthy pipeline is the pairing of a scanner invocation with credential-store and environment reads it has no reason to make, and outbound traffic to a destination that is not the scanner's own update or vulnerability-database endpoint, with the reference in the workflow file being a mutable tag rather than a commit SHA as the precondition that made it possible.

For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry.

SecurityWeek, citing SOCRadar

March 19, 2026 (~17:43 UTC): The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits.

Aqua Security 2026-04-01

We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow.

LiteLLM (BerriAI) 2026-03-24

GitHub's release UI displayed "Immutable" badges next to each poisoned tag. The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the "Immutable" indicator. Pinning to full commit SHAs remains the only truly immutable protection.

Aqua Security 2026-04-01

We assess with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP.

CERT-EU 2026-04-02

Builds on: 2026-08-06/litellm-callback-hook-post-inference-tool-call-forgery

threat15 Aug 06:20Zmulti-sourceOpen finding ↗

2026-08-08 · view entry permalink →

NOTABLENATOB2

Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people

Wiz Research's semi-annual cloud threat report covers January to June 2026, and its value for this constituency is the named inventory rather than the trend lines: it says concretely which AI infrastructure attracted attacker and researcher attention, and what the resulting exposure looks like in a cloud estate.

The AI toolchain now has its own vulnerability cadence. LiteLLM (an AI gateway Wiz says is present in over a third of the cloud environments it monitors) "had four separate security events in six months: a supply-chain compromise, an SQL injection vulnerability exploited in the wild, a privilege escalation chain and an authentication bypass", while Dify, Langflow, n8n and Ollama "each had critical unauthenticated vulnerabilities of their own" (Wiz Research, 2026-08-06). That list is worth reading as an asset-inventory prompt: these are components teams stand up quickly, often outside the change process that governs the rest of the estate, and three of the five have already reached this pipeline's coverage through separate exploited-vulnerability events.

The exposure finding is sharper than the vulnerability one. On Model Context Protocol servers, Wiz reports: "We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services" (Wiz Research, 2026-08-06). The reason that shape matters is that an MCP server is not a data store to be broken into; it is a component that already holds the credentials for everything behind it and exists to act on their behalf, so reaching it unauthenticated is not a step toward access, it is the access.

On the actor side, Wiz profiles JINX-0163, a cloud-native extortion group it began tracking in 2026 and that "consistently targets non-human identities - service accounts and IAM roles - rather than end users", in some cases leveraging a single over-privileged identity or an exposed state file to pivot to a full inventory (Wiz Research, 2026-08-06). An extortion group that skips human identity entirely bypasses most of the control stack organisations have spent two years building (phishing-resistant MFA, conditional access, helpdesk verification) none of which applies to a service account.

On supply chain, Wiz records that notable supply-chain attacks "went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026", with TeamPCP, North Korea and at least three independent operations running campaigns concurrently across npm, PyPI, Composer, VSCode extensions, Jenkins plugins and AUR, several of which had not been targeted this way before (Wiz Research, 2026-08-06). It also notes that malicious packages' shrinking availability window is what makes an install cooldown policy effective (declining to download packages published less than 24 hours ago) which is a specific, cheap control rather than a general recommendation.

We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services.

They went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026.

Wiz Research 2026-08-06
annual-report08 Aug 05:22Zsingle-sourceOpen finding ↗
Sources: Wiz Research

2026-08-06 · view entry permalink →

NOTABLENATOB2

LiteLLM callback hooks let an attacker who already holds gateway admin forge tool calls after inference, downstream of every prompt-level defence

An attacker who already holds administrative access to a LiteLLM proxy (through leaked master-key or proxy-admin credentials, a prior vulnerability chain, or a supply-chain compromise) can use the gateway's legitimate model-update management API to change a model's configured backend address, silently routing that model's traffic through infrastructure they control and exposing the provider API keys that resolve at request time (Cloud Security Alliance, 2026-08-05). With traffic rerouted, the interesting part is what the relay does next: it abuses LiteLLM's own post-call callback hooks, the extension points the platform provides for logging and response processing, so that an attacker in control of these hooks can inject arbitrary text into a response or, more consequentially, forge a tool call that was never produced by the underlying model (Cloud Security Alliance, 2026-08-05). The technique originates in research published two days earlier under the handle wunderwuzzi (Embrace The Red, 2026-08-03).

The consequence worth internalising is architectural rather than novel-exploit. Because the manipulation happens after the model has already generated its output, it bypasses prompt-level defenses entirely (Cloud Security Alliance, 2026-08-05). Every control an organisation has invested in at the prompt layer (system-prompt hardening, input filtering, injection detection, guardrail models) sits upstream of the tamper point and cannot see it. If the agent downstream of the gateway acts on tool calls, a forged tool call is an instruction to act, and it arrives carrying the gateway's own authenticity.

This is post-compromise, and that framing should govern how urgently it is treated: it is not a way in, it is what a foothold on the gateway is worth. But it inverts a common assumption about AI-agent architecture, in which the gateway is treated as plumbing and its admin credential as ordinary application configuration. On this evidence the gateway is a control-plane component whose compromise is not contained by anything downstream of it. The reporting also notes that a capable attacker reverts the rerouted configuration once finished, which removes the most visible artifact of the compromise (Cloud Security Alliance, 2026-08-05), so a point-in-time configuration review is exactly the check that will come back clean.

Triage: legitimate operations change model configuration too, adding models, moving between regions, failing over to a secondary provider. The discriminators are that the change is made outside a deployment pipeline or change window, that the new backend address is not one of the organisation's known provider or proxy endpoints, and above all that the configuration is changed and then changed back within a short interval, which is not a shape ordinary operational work produces.

forge a tool call that was never produced by the underlying model

bypasses prompt-level defenses entirely

Cloud Security Alliance, Lab Space 2026-08-05
research06 Aug 04:11Zmulti-sourceOpen finding ↗