IT researchers have gained access to the leaked data of thousands of companies from the LiteLLM supply chain attack in March.

Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ organizations.

The March 2026 LiteLLM supply chain attack likely affected over 2,500 organizations and exposed over 430,000 CI/CD pipelines.