Largest AI Supply-Chain Breach of 2026 Exposes Over 2,500 Companies
Pramod
Founder & CEO
Security researchers disclosed what they described as the largest AI supply-chain breach identified so far in 2026, with more than 2,500 organizations and roughly 434,000 CI/CD pipelines potentially exposed.
The attack, attributed to a group tracked as Team PCP, compromised versions 1.82.7 and 1.82.8 of the LiteLLM PyPI package. Investigators traced the initial entry point to the Trivy security scanner used within LiteLLM's own build pipeline, which remained compromised for roughly 20 days before being caught.
High-confidence matches among affected organizations reportedly included Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Siemens, Deloitte, and Vodafone, among others. The FBI issued a FLASH advisory the following month warning that credentials harvested during the exposure window could still be weaponized in future attacks, urging affected organizations to rotate secrets and audit downstream activity even after the malicious package was removed.