In a supply chain attack on the popular LiteLLM library in March of this year, attackers injected compromised packages into the Python Packages Index (PyPI). These were apparently downloaded and used tens of thousands of times by automated build systems, affecting more than 2500 well-known companies – even though the compromised packages were only online for 40 minutes.

The attackers potentially infiltrated around 434,000 automated developer build pipelines used by more than 2500 companies, IT security researchers from CloudSEK explain in a blog post. The data indicates that attackers could have accessed it, but does not prove that they did so and that all credentials were stolen. According to the analysts, the threat is still current, as the FBI also warned in July that actors associated with the cybercrime group TeamPCP are likely to misuse stolen credentials long after the actual attack. Therefore, potentially affected parties should take security measures such as changing credentials, closing potential vulnerabilities, and hardening systems, recommend the IT researchers.

The list of affected companies includes some large and well-known firms. Airbus, Amazon Web Services, Cisco, Hoffmann-La Roche AG, Salesforce, Samsung, ServiceNow, Siemens, but also Epic Games, FedEx, the reinsurance giant Munich Re, Robert Bosch GmbH, Thales Group, Volkswagen AG, or X Corp appear there. The attackers have obtained secrets such as credentials from some of them and many others, but in all cases, the compromised versions ran in the automated AI build systems – sometimes thousands of times.