people · May 16, 2026
LiteLLM Supply Chain Compromise Enables Lateral Movement Across Kubernetes Clusters
Share the canonical public link.
Compromise of LiteLLM allowed attackers to move laterally across Kubernetes clusters and exfiltrate data during the TeamPCP campaign. LiteLLM functions as an AI gateway proxy used by thousands of enterprises to route requests to large language model providers. The single-tool compromise formed part of broader supply chain activity that began with Trivy on March 20, 2026. The article was published on May 15, 2026, eleven hours before the current date.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)