CloudSEK said that over 2,500 companies and 4,34,000 CI/CD pipelines across the world were exposed in the supply chain breach. The attack occurred in March 2026, and the threat actor group TeamPCP orchestrated a supply chain attack targeting AI infrastructure by compromising LiteLLM. The attack reportedly exposed data of companies including MediaTek, Microsoft, X, Amazon, Cisco, Samsung and Salesforce.

