Artificial Intelligence
LiteLLM cyberattack exposes over 2,500 companies to risk
Two malicious versions of LiteLLM—a tool for managing multiple AI models—were exposed for 40 minutes, risking credential theft for affected companies.
- Popular AI proxy LiteLLM compromised in supply chain attack
- Supply chain’s invisible risks can’t wait for the patch
- 1
Ukrainian police bust over 100 fraudulent call centers
- 2
Lazarus leverages fake job offers as gateway to aerospace attacks
- 3
US establishes weapons systems testing centre in Morocco
- 4
Schools are becoming a new cybersecurity battleground
- 5
Humanoid robots are already here—and they can crawl, breakdance, and backflip
- Alberto Payo
- Technology Journalist
- Published on
17 August 2026 at 07:05
More than 2,500 companies could have been exposed by a cyberattack against LiteLLM, a tool used for working with artificial intelligence models.
The incidentmay have also potentially affected about 434,000 systemsused by companies to develop and update their programs.
The attack took place in March, and the perpetrators introduced malicious code into two versions of LiteLLM that were available for about 40 minutes. The goal was to exploit these programs to access information stored on the computers and systems of the companies that installed them.
According to CloudSEK, which has published a report on the incident detailing the number of victims, the attackers were able to search for passwords and access keys to cloud services, code repositories, internal systems, and artificial intelligence services.
“The stolen object was cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys,” explains the company.
The affected
Among the companies listed as potentially exposed are names like AWS, Samsung, Cisco, Salesforce, Siemens, Airbus, FedEx, Volkswagen, Deloitte, Orange, Vodafone, Thales, and Epic Games.
CloudSEK clarifies that appearing on their list does not mean that these companies have necessarily been hacked, but that there are indications of possible exposure that should be investigated.
Additionally, the firm recommends organizations check if they used the affected versions and, if so, change the passwords and keys that may have been within reach of the attackers. Deleting the malicious program is not enough, as the stolen passwords could remain functional for weeks or months.
The case of LiteLLM is a clear example ofthe dangers of supply chain attacks, where criminals do not need to directly enter a large company but can first attack one of its trusted providers, programs, or tools.
In this way, a single compromised component can serve as an entry point to many organizations at the same time. Thus, it is increasingly evident that security no longer depends solely on protecting one’s own systems, but it is also necessary to know and monitor what software and services companies use, as an apparently legitimate tool can become the weakest link in the entire chain.
The affected
Become a premium member for free!
You may be interested in
- Artificial IntelligencePopular AI proxy LiteLLM compromised in supply chain attackAlberto Payo
- Artificial IntelligenceSupply chain’s invisible risks can’t wait for the patchAlberto Payo
- Artificial IntelligenceAI hacks gym booking system, boots user to nab class spotAlberto Payo
- Artificial IntelligenceAnother AI model escapes its sandbox to search the web for answersAlberto Payo
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 2) { //TIEMPO
var respuesta =
“No ha pasado aún un minuto desde tu último comentario. Espera un poco y podrás comentar de nuevo una noticia.
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 3) { //PALABROTA
var respuesta = “Por favor, utiliza un lenguaje correcto para comentar las noticias.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else { //NO LOGUEADO
var respuesta =
“Lo sentimos, al parecer no tienes una sesión iniciada. Vuelve a Iniciar Sesión y podrás publicar este comentario.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarPositivo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘positivo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var likes = parseInt($(“#like_” + id_comentario + ” span”).text());
$(“#like_” + id_comentario + ” span”).text(parseInt(likes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarNegativo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘negativo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var dislikes = parseInt($(“#dislike_” + id_comentario + ” span”).text());
$(“#dislike_” + id_comentario + ” span”).text(parseInt(dislikes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function recargar_widgets_sesion() {
recargar_cabecero_sesion();
recargar_menu_sesion();
recargar_comentar_sesion();
recargar_comentar_comentar();
comprobar_user_sesion_215_articulo(0);
}
function iniciarSesion() {
var continuar = true;
var msg = “”;
var usuario_log = $(“#usuario_log”).val();
var password_log = $(“#password_log”).val();
var valor_periodico = $(‘#valor_periodico’).val();
// console.log(valor_periodico);
if (usuario_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico n”;
}
if (password_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar la contraseña.n”;
}
if (continuar) {
$.ajax({
type: “POST”,
data: $(“#formulario_login”).serialize(),
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/login-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
// console.log(data);
if (data == 1) {
recargar_widgets_sesion();
$(“#modal-login .modal-action.modal-close.close-btn”).trigger(“click”);
$(“#usuario_log”).val(“”);
$(“#password_log”).val(“”);
if (window.location.href.includes(“area-usuario”)) {
// window.location.reload();
}
} else {
var respuesta =
“No hemos encontrado ningún usuario con el correo electrónico y la contraseña introducidos. Por favor, vuelve a intentarlo o recupera la contraseña pulsando el botón inferior.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function comprobar_user_sesion_215_articulo(es_premium) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
} else {
// $(“#art-cuerpo-visible”).removeClass(“art-cuerpo-visible”);
// $(“#art-cuerpo-visible”).addClass(“art-cuerpo-no-visible”);
if (es_premium) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“d-none”);
$(“#art-cuerpo-visible-premium”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“d-none”);
$(“#banner-premium”).removeClass(“d-none”);
} else {
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
}
}
}
});
}
function comprobar_user_sesion_215() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(‘.col-comparador-registro-login’).addClass(‘w-auto’)
} else {
$(‘.col-comparador-registro-login’).removeClass(‘w-auto’)
}
}
});
}
function cerrarSesion() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/delete-session-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
recargar_widgets_sesion();
$(“#offCanvasClose”).trigger(“click”);
if (window.location.href.includes(“area-usuario”)) {
window.location.href = ‘/’;
}
}
});
}
function registrarCuenta() {
var continuar = true;
var msg = “”;
var email_registro = $(“#email_reg”).val();
var pass_registro = $(“#password_reg”).val();
var pass_registro2 = $(“#password_reg_2”).val();
var nombre_registro = $(“#nombre_reg”).val();
var apellidos_registro = $(“#apellidos_reg”).val();
var ref_id_periodico = $(“#ref_id_periodico”).val();
if (pass_registro2 != pass_registro) {
continuar = false;
msg += “Deben coincidir ambas contraseñas. n”;
}
if (email_registro.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico. n”;
}
// if (pass_registro.length < 8) {
// continuar = false;
// msg += “Cal omplir la contrasenya amb un mínim de 8 caràcters. n”;
// }
if (nombre_registro.length == 0) {
continuar = false;
msg += “Hay que llenar el nombre. n”;
}
if (!$(“#aceptopoliticas”).is(“:checked”)) {
continuar = false;
if (ref_id_periodico == 8) {
msg += “You must accept the privacy policy. n”;
} else {
msg += “Debes aceptar la política de privacidad. n”;
}
}
if (continuar) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(“#formulario_registro”).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/register-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
if (data == 0) {
var respuesta = “Este correo electrónico ya está registrado.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else {
var respuesta = “¡Enhorabuena! Te has registrado con éxito.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
recargar_widgets_sesion();
$(“#email_reg”).val(“”);
$(“#password_reg”).val(“”);
$(“#nombre_reg”).val(“”);
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function recuperarPass() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#formulario_recuperarpass’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/reset-pass-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
var respuesta =
“Revisa tu e-mail y sigue las instrucciones para recuperar tu contraseña.”;
Swal.fire({
text: respuesta,
icon: “info”
});
$(“#modal-pass .modal-action.modal-close”).trigger(“click”);
$(“email_recuperar”).val(“”);
}
});
}
function resetearPass() {
if ($(“#nuevo-pass”).val() == $(“#nuevo-pass-repeat”).val()) {
if ($(“#nuevo-pass”).val().length >= 8) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#resetear-clave’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/resetear-pass.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
$(“#email_recuperar”).val(“”);
var respuesta = “La contraseña se ha actualizado. Ya puedes volver a Iniciar Sesión.”;
Swal.fire({
text: respuesta,
icon: “success”
}).then((result) => {
window.location.href = ‘http://www.escudodigital.com/’;
});
}
});
} else {
var respuesta = “La contraseña debe tener un mínimo de 8 caracteres.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
} else {
var respuesta = “Ambas contraseñas deben coincidir.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
$(document).ready(function() {
recargar_widgets_sesion(); //DESCOMENTAR ESTO
});
‘)
.text(msg)
.insertAfter($el);
}
function esEmailValido(email) {
return /^[^s@]+@[^s@]+.[^s@]{2,}$/.test(String(email).trim());
}
function validar() {
limpiarErrores();
let ok = true;
const $nombre = $(“#nombre”);
const $email = $(“#email”);
const $motivo = $(“#motivo”);
const $check = $(“#checkbox”);
const nombre = $nombre.val().trim();
const email = $email.val().trim();
const motivo = $motivo.val().trim();
if (nombre.length < 2) {
marcarError($nombre, “Enter your full name.”);
ok = false;
}
if (!esEmailValido(email)) {
marcarError($email, “Enter a valid email.”);
ok = false;
}
if (motivo.length < 5) {
marcarError($motivo, “Briefly explain how we can help you.”);
ok = false;
}
if (!$check.is(“:checked”)) {
marcarError($check, “You must accept the legal terms.”);
ok = false;
}
return ok;
}
function setLoading(isLoading) {
$btn.prop(“disabled”, isLoading);
$btn.text(isLoading ? “Sending…” : “Sent”);
}
function submitFormWithToken(token) {
setLoading(true);
const payload = {
nombre: $(“#nombre”).val().trim(),
email: $(“#email”).val().trim(),
motivo: $(“#motivo”).val().trim(),
legal: $(“#checkbox”).is(“:checked”) ? 1 : 0,
periodico_id_periodico: 8,
periodico: ‘www.escudodigital.com’,
url: window.location.href,
periodico_nombre: ‘DigitalShield’,
token: token
};
$.ajax({
url: URL_ENDPOINT,
method: “POST”,
data: payload,
dataType: “json” // Expects JSON response from server
})
.done(function(res) {
if (res && (res === 1 || res === “1” || res.ok)) {
$(“#msgFormContacto”).html(‘Message sent successfully.
‘);
$form[0].reset();
} else {
$(“#msgFormContacto”).html(‘Message not sent. Try again.
‘);
}
})
.fail(function(xhr) {
$(“#msgFormContacto”).html(‘Connection error. Try again.
‘);
})
.always(function() {
setLoading(false);
});
}
$btn.on(“click”, function(e) {
e.preventDefault();
e.stopPropagation(); // Stop default button behavior if any
if (!validar()) return;
// Execute reCAPTCHA
if (window.grecaptcha) {
grecaptcha.ready(function() {
grecaptcha.execute(RECAPTCHA_SITE_KEY, {
action: ‘submit’
}).then(function(token) {
submitFormWithToken(token);
});
});
} else {
// Fallback or error if grecaptcha not loaded
alert(“reCAPTCHA not loaded. Please refresh.”);
}
});
$(“#nombre,#email,#motivo,#checkbox”).on(“input change”, function() {
$(this).removeClass(“is-invalid”);
$(this).next(“.error-text”).remove();
});
});
