London Stock Exchange Group PLCLondon Stock Exchange Group is listed among potentially affected organizations, risking exposure of credentials and source code.
CloudSEKは、2026年3月にLiteLLMが関与した大規模なAIサプライチェーンインシデントによって、2500を超える組織が影響を受けた可能性があると特定した。この侵害には約43万4000件の自動化されたソフトウェア開発パイプラインが関連している。影響を受けた可能性のある組織は、テクノロジー、サイバーセキュリティ、銀行・金融サービス、通信、製造、コンサルティング、物流、エンタープライズソフトウェアなどの重要産業にわたり、NVIDIA、サムスン電子、シスコシステムズ、シーメンス、S&Pグローバル、ServiceNow、デロイト、ボーダフォン、Xコーポレーション、Zscaler、フェデックス、フォルクスワーゲン、タレス、ロンドン証券取引所グループなど、世界の主要組織と高い確度で一致するものが含まれている。このインシデントは、サイバー犯罪グループ「Team PCP」がLiteLLMを侵害した後に発生した。悪意のあるバージョンはPythonソフトウェアリポジトリのPyPIで約40分間のみ入手可能だったとされるが、CloudSEKの分析では、この侵害に関連する可能性のあるCI/CDパイプラインが約43万4000件特定された。侵害された可能性のある情報には、クラウド認証情報、ソースコードへのアクセス、サーバーキー、ソフトウェア開発の秘密情報、AIのAPIキー、その他の認証情報が含まれ、攻撃者が重要なビジネスシステムにアクセスできる可能性がある。CloudSEKは、データセットに含まれていることが必ずしも組織が実際に侵害されたことを意味するわけではないが、緊急に調査すべきだと強調している。CloudSEKは、組織に関連する認証情報やインフラが特定されたデータセットに含まれているかどうかを確認できる無料の侵害チェックツールを公開した。
London Stock Exchange Group PLCLondon Stock Exchange Group is listed among potentially affected organizations, risking exposure of credentials and source code.
Samsung Electronics Co LtdSamsung is listed as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and source code.
ServiceNow IncServiceNow is identified as potentially impacted, facing possible exposure of cloud credentials and development secrets.
NVIDIA CorporationNVIDIA is listed as a high-confidence match, potentially exposed to credential and source-code leaks via the compromised LiteLLM.
Space Exploration Technologies Corp. Class A Common Stock
Zscaler IncZscaler is named as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and secrets.
Cisco Systems IncCisco is listed as potentially impacted by the LiteLLM supply chain compromise, with possible exposure of credentials and source code.
Thales S.A.Thales is listed as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and source code.
ZSCALER INC. DL-,001
Vodafone Group PLCVodafone is identified as potentially impacted by the AI supply chain incident, with possible exposure of credentials and secrets.
S&P Global IncS&P Global is among potentially affected organizations, with possible exposure of sensitive credentials and system access.
Siemens AktiengesellschaftSiemens is named as potentially affected, with risk of credential and source-code exposure from the compromised LiteLLM.
Volkswagen AGVolkswagen is listed among potentially impacted organizations, facing potential exposure of credentials and development secrets.
FedEx CorporationFedEx is named among potentially affected organizations, with risk of credential and system access exposure.