FAIL · AI INCIDENT TRACKER

wire / 2026-08-11-8e67

LiteLLM AI Supply Chain Attack Exposes 2,500+ Organizations Worldwide

August 11, 2026 · USA INCIDENT ECONOMICRIGHTS

A poisoned dependency in LiteLLM reached 2,500 organizations and 434,000 pipelines before anyone noticed. AI infra ships with the usual open-source hygiene.

The facts

A supply chain attack in March 2026 compromised the LiteLLM AI library, impacting over 2,500 organizations and 434,000 software pipelines globally. Malicious code, introduced via a compromised dependency, exposed sensitive credentials and keys, risking data breaches and unauthorized access across critical industries. The incident highlights vulnerabilities in AI infrastructure supply chains.