From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack | #ransomware | #cybercrime


By the Hudson Rock Threat Intelligence Team

Following our initial report detailing the largest AI supply chain breach of the year, Hudson Rock’s threat intelligence team has continued to analyze the catastrophic fallout of the LiteLLM and Trivy supply chain campaign. As part of our global ethical disclosure efforts, we have reconstructed the attack paths likely used by threat actors to compromise enterprise environments worldwide.

A Critical Note on Blame: It is highly important to emphasize that these breaches were extremely difficult to avoid. The affected organizations are not at fault. This sophisticated supply chain compromise exploited deep, trusted dependencies within standard DevOps pipelines, successfully bypassing traditional security perimeters.

This blog serves as an urgent call to action. Our goal is not to point fingers, but to provide transparency and urge companies to claim their ethical disclosures and lock down their environments before this exfiltrated data begins to circulate more heavily among opportunistic cybercriminals.

The LiteLLM/Trivy data gives us rare and terrifying insight into how organizations suffered devastating ransomware attacks lately. By analyzing the compromised CI runner dumps, we can map exactly what the threat actors likely obtained before launching their extortion campaigns.

Global Ethical Disclosures: Over the last few days, Hudson Rock has completed over 250 ethical disclosures to organizations worldwide, working tirelessly to alert enterprises to their exposed cloud infrastructure before threat actors could weaponize the data. Additionally, we have provisioned the intelligence data directly to our cybersecurity partners so they can immediately protect their own customers.

Healthcare & Life Sciences

Below, we deep dive into the high-profile organizations compromised in this campaign and detail the exact secrets, tokens, and configurations that likely fueled downstream extortion by groups like Vect ransomware (TeamPCP).

Vect ransomware group leak site tracking the TeamPCP LiteLLM/Trivy campaign victims. These harvested credentials directly fueled downstream extortion. Both organizations are now actively listed on leak sites. (Image via www.ransomware.live)


1. Guesty

The Breach: The property management software company Guesty suffered a direct hit to their critical cloud infrastructure. As seen on the leak sites above, this data was quickly weaponized for extortion.

How Hackers Likely Got In: Based on our analysis of the compromised CI runner dumps and public reports, it is assessed that threat actors likely gained access to critical cloud infrastructure, specifically exposing dozens of AWS Access Keys and secrets directly from Guesty’s CI pipelines. The raw pipeline logs dumped the credentials in plain text, which likely granted the attackers administrative access to their cloud environments.

Outcome of the Breach: According to the Vect ransomware group, the data stolen from Guesty includes internal projects, 4 million sent/received emails with attachments, their entire userbase, and highly sensitive Airbnb and Booking.com integration data. The total data size extorted is reported to be 700GB.

Guesty CI Runner dump showing AWS and Kubernetes secrets

Compromised CI runner dumps for Guesty.com revealing exposed AWS and Kubernetes secrets.


2. S&P Global

The Breach: For S&P Global, the blast radius of this supply chain attack is massive. Like Guesty, S&P Global’s harvested credentials directly fueled downstream extortion and resulted in them being listed on the Vect ransomware group’s leak site.

How Hackers Likely Got In: Evidence suggests threat actors likely intercepted temporary AWS STS session tokens and long-lived AWS keys during a terraform-actions workflow. The sheer volume of exposed data is staggering: judging by the telemetry, attackers likely accessed thousands of secrets, GitHub tokens, JWTs, and RSA private keys, fundamentally compromising their internal repository and cloud security architecture.

Outcome of the Breach: According to the Vect ransomware group leak site, the threat actors successfully exfiltrated 250GB of highly confidential data, including internal projects, core architectural secrets, and active API keys.

S&P Global Secrets Overview

Overview of the thousands of secrets extracted from S&P Global’s infrastructure inside Hudson Rock’s Cavalier portal.

S&P Global CI Runner Dump

Deep dive into the S&P Global runner environments, showing GitHub tokens and ECR repository URLs exposed.


3. Cisco

The Breach: Cisco’s source code was stolen in a breach linked directly to a compromised development environment running a poisoned Trivy container. The attackers likely infiltrated critical repositories, including cisco-it-cloud-infrastructure.

BleepingComputer article on Cisco breach

Public reporting via BleepingComputer confirming the Cisco source code theft via the Trivy-linked breach.

How Hackers Likely Got In: Judging by the environment dumps, it appears the attackers likely scraped GitHub Personal Access Tokens (PATs) and highly sensitive API keys from the runner’s environment variables. The exposure of an Artifactory token likely allowed access to internal packages, while a Conjur API key appears to have provided a foothold into Cisco’s broader secret management infrastructure.

Cisco GitHub Actions config

Cisco GitHub Actions runner environment dump showing the compromised Trivy action path and internal repository links.

Cisco Secrets Dump

Exfiltrated environment configuration from Cisco revealing highly sensitive Conjur, GitHub, and JIRA secrets.


4. European Commission

The Breach: The European Commission suffered a severe cloud breach resulting from this campaign. The compromised runner was executing a Terraform deployment for AWS infrastructure.

CERT-EU Press Release

Public statement via CERT-EU regarding the cybersecurity incident affecting the europa.eu AWS infrastructure.

How Hackers Likely Got In: Telemetry indicates attackers likely obtained AWS IAM credentials directly from the environment, granting administrative cloud access. Furthermore, a hardcoded SSH private key and GitLab CI tokens appear to have been exposed, which would likely allow the threat actors to pivot laterally across the European Commission’s GitLab infrastructure.

European Commission GitLab Runner variables

Raw exfiltrated log from the European Commission breach highlighting exposed AWS access keys and GitLab tokens.


5. Mercor

The Breach: Mercor, a $10 billion AI startup, faced a catastrophic security incident impacting their AI annotation and RL Studio platform resulting from the LiteLLM supply chain attack.

Mercor Security Incident Update

How Hackers Likely Got In: Based on the data, it appears attackers likely exfiltrated local configuration files and runner environment variables. This would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.

Mercor Compromised Secrets in Cavalier

Hudson Rock Cavalier view showing the exact compromised Mercor environment variables, including Anthropic, Linear, and Datadog API keys inside Cavalier (secrets blurred for safety).

Outcome of the Breach: The fallout for Mercor has been monumental. According to available reports, attackers moved laterally through Mercor’s systems and extracted approximately 4 Terabytes of data. This included 939 GB of proprietary source code, potential AI training methodologies, video interviews, and user database records containing the Social Security numbers and biometric data of over 40,000 contractors. Meta subsequently paused a major data contract, and multiple class-action lawsuits have been filed.

Lapsus$ Statement on Mercor Data

The Lapsus$ extortion group claiming to have permanently sold the entirety of Mercor’s biometric, PII, and AI training data to Chinese enterprises.


6. Telnyx

The Breach: Telecom and communications platform Telnyx was breached through their internal infrastructure via malicious Python SDK packages tied to the broader campaign.

Telnyx Security Advisory

Telnyx advisory detailing the malicious SDK versions linked to the Trivy/LiteLLM campaign.

How Hackers Likely Got In: According to the data dumps, it is assessed that attackers likely recovered Docker configuration files containing base64-encoded basic authentication credentials and GitHub PATs. This would have allowed threat actors to pull and push directly to Telnyx’s internal production and development container registries.

Telnyx Secrets in Cavalier

Hudson Rock Cavalier view displaying the exfiltrated Docker configuration and GitHub tokens from Telnyx’s environment (secrets blurred for safety).

Outcome of the Breach: On March 27, 2026, two unauthorized versions of the Telnyx Python SDK (4.87.1 and 4.87.2) were published to PyPI containing malicious credential-stealing code. Telnyx publicly confirmed the incident, clarifying that while the PyPI distribution channel was compromised, the Telnyx platform, APIs, customer data, and voice/messaging infrastructure itself were not compromised.




Click Here For The Original Source.

——————————————————–

..........

.

.