Security researchers this week confirmed the scale of what’s being called one of 2026’s largest AI supply-chain attacks. LiteLLM, a popular open-source tool that lets businesses route requests to different AI models, was compromised earlier this year — and the fallout has just gone public. Attackers pushed malicious versions of the package that quietly harvested credentials the moment a developer’s system loaded them.
The numbers are striking: 153GB of stolen data, pulled from over 118,000 automated build runs, tied to more than 2,500 organisations including AWS, Samsung, Cisco, Salesforce and Siemens. The stolen material included AWS and Azure keys, Salesforce tokens, SSH keys, Kubernetes access tokens, and API keys for AI providers — the kind of credentials that, once leaked, let an attacker move quietly into cloud infrastructure rather than just one system.
You don’t need to be a household name to be caught up in this. The attack didn’t target big companies specifically — it targeted a widely used piece of AI infrastructure that thousands of smaller businesses and their developers rely on too, often without anyone outside the tech team knowing it’s there.
Why this matters even if you’ve never heard of LiteLLM
Most UK SMEs don’t build their own AI tools from scratch. They buy an off-the-shelf product, hire a developer, or work with an agency — and that agency’s toolchain is exactly where things like LiteLLM live. If your business has had any custom AI feature built in the last year — a chatbot, an internal automation, an AI-powered search — it’s worth asking directly whether that build touched LiteLLM or a similar AI proxy tool, and if so, whether credentials have been rotated since.
This is also a reminder that “supply chain” doesn’t just mean physical goods anymore. A single compromised open-source package, published to a trusted registry, can sit quietly for months before anyone notices — this breach happened in March and has only now become fully clear. The attackers didn’t need to break into anyone’s systems directly; they compromised the build pipeline of a widely trusted tool and let thousands of businesses install the malicious version themselves, simply by updating a dependency the way any development team routinely does.
That’s the uncomfortable part of this story. Nobody did anything careless. Keeping software dependencies up to date is standard good practice, not a mistake — which is exactly why supply-chain attacks like this one are so effective and why they keep happening across different ecosystems, from JavaScript packages to Python tools like LiteLLM.
What to actually do about it
Ask your developer or agency directly. A short, specific question — “did any of our systems use LiteLLM, and have we rotated credentials since March?” — is enough to get a real answer. If you don’t get a clear one, that’s itself worth noting.
Rotate anything that touched a compromised pipeline. API keys, cloud access keys and tokens are cheap to reissue and expensive to leave exposed. If there’s any doubt, rotate rather than assume.
Treat AI tooling like the infrastructure it now is. A year ago, “AI tool” often meant a chat window. Today it can mean a proxy sitting between your systems and multiple AI providers, holding credentials for all of them. It deserves the same access controls and monitoring as your core cloud accounts, not an afterthought bolted on by whoever set it up first.
If your business is building or has built custom AI features and you’re not confident the underlying stack has been properly secured, CoolCoding handles exactly this kind of technical implementation and credential hygiene work, and KeepSafe can monitor for signs your business’s data has surfaced in a breach like this one.
The takeaway
This breach didn’t happen because a business did something wrong — it happened because a tool they trusted was compromised upstream. The response isn’t panic, it’s a straightforward audit: know what AI tooling sits behind your systems, ask whether it’s been affected, and rotate credentials if there’s any doubt. Five minutes of asking the right question now beats months of not knowing later.