August 12, 2026 · Ars Technica
Supply-chain attack on AI gateway tool exposed 2,500+ firms
Attackers compromised the widely used LiteLLM AI gateway library by pushing two poisoned versions to PyPI, exposing cloud credentials, SSH keys, CI/CD secrets, and LLM API keys across more than 2,500 organizations and roughly 434,000 CI/CD pipelines. Affected companies reportedly span tech, finance, and manufacturing.
Why it matters: LiteLLM sits in the AI infrastructure stack of many companies' agent and API deployments, so this shows the fast-growing AI tooling supply chain is now a high-value attack target. It follows the same package-poisoning pattern as recent NPM/PyPI incidents, but at a scale specific to AI infrastructure.