securityaffairs.com 8/17/2026, 6:21:08 PM · external

TeamPCP compromises LiteLLM, leaking keys at Microsoft, Deloitte

TeamPCP compromises LiteLLM, leaking keys at Microsoft, Deloitte
CyberSIXT Evidence Panel
Primary Source resecurity.com
Threat Actor

THE LiteLLM Supply-Chain Attack, attributed to the threat actor group TeamPCP, has compromised credentials across 2,038 repositories, with substantial impacts on various sectors, especially technology, finance, and healthcare. The attack exploited a backdoor in the LiteLLM open-source AI application, affecting over 2,500 organizations and exposing critical credentials like cloud keys and API tokens.

Security experts caution that many victim organizations remain unaware of the breach, emphasizing the need for credential rotation and revocation. Key affected companies include Microsoft, IBM, and Deloitte, among others, highlighting the widespread risk across industries.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline