// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

LiteLLM

DISCLOSED 2026-08-13 · SUPPLY CHAIN

LiteLLM was compromised through the Trivy hack and used to distribute information-stealing malware to its users. The attack impacted over 2,500 organizations. The text does not specify the type of data stolen or the exact date of the breach.

The record

What we know

Disclosed
2026-08-13
Attack vector
Supply Chain
Sector
technology
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

A positive-security model might have detected unauthorized changes from the supply chain compromise, but the text does not specify whether the malware executed on endpoints or how it was delivered, so it is unclear if it would have been blocked.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other supply chain breaches on file

This page is the permanent ColdRecon entry for the LiteLLM disclosure. It updates if new public reporting emerges. All tracked breaches →

LiteLLM just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →