By the Hudson Rock Threat Intelligence Team
Following our initial report detailing the largest AI supply chain breach of the year, Hudson Rock’s threat intelligence team has continued to analyze the catastrophic fallout of the LiteLLM and Trivy supply chain campaign. As part of our global ethical disclosure efforts, we have reconstructed the attack paths likely used by threat actors to compromise enterprise environments worldwide.
This blog serves as an urgent call to action. Our goal is not to point fingers, but to provide transparency and urge companies to claim their ethical disclosures and lock down their environments before this exfiltrated data begins to circulate more heavily among opportunistic cybercriminals.
The LiteLLM/Trivy data gives us rare and terrifying insight into how organizations suffered devastating ransomware attacks lately. By analyzing the compromised CI runner dumps, we can map exactly what the threat actors likely obtained before launching their extortion campaigns.
Global Ethical Disclosures: Over the last few days, Hudson Rock has completed over 250 ethical disclosures to organizations worldwide, working tirelessly to alert enterprises to their exposed cloud infrastructure before threat actors could weaponize the data. Additionally, we have provisioned the intelligence data directly to our cybersecurity partners so they can immediately protect their own customers.
Healthcare & Life Sciences
Below, we deep dive into the high-profile organizations compromised in this campaign and detail the exact secrets, tokens, and configurations that likely fueled downstream extortion by groups like Vect ransomware (TeamPCP).
1. Guesty
The Breach: The property management software company Guesty suffered a direct hit to their critical cloud infrastructure. As seen on the leak sites above, this data was quickly weaponized for extortion.
How Hackers Likely Got In: Based on our analysis of the compromised CI runner dumps and public reports, it is assessed that threat actors likely gained access to critical cloud infrastructure, specifically exposing dozens of AWS Access Keys and secrets directly from Guesty’s CI pipelines. The raw pipeline logs dumped the credentials in plain text, which likely granted the attackers administrative access to their cloud environments.
Outcome of the Breach: According to the Vect ransomware group, the data stolen from Guesty includes internal projects, 4 million sent/received emails with attachments, their entire userbase, and highly sensitive Airbnb and Booking.com integration data. The total data size extorted is reported to be 700GB.

Compromised CI runner dumps for Guesty.com revealing exposed AWS and Kubernetes secrets.
2. S&P Global
The Breach: For S&P Global, the blast radius of this supply chain attack is massive. Like Guesty, S&P Global’s harvested credentials directly fueled downstream extortion and resulted in them being listed on the Vect ransomware group’s leak site.
How Hackers Likely Got In: Evidence suggests threat actors likely intercepted temporary AWS STS session tokens and long-lived AWS keys during a terraform-actions workflow. The sheer volume of exposed data is staggering: judging by the telemetry, attackers likely accessed thousands of secrets, GitHub tokens, JWTs, and RSA private keys, fundamentally compromising their internal repository and cloud security architecture.
Outcome of the Breach: According to the Vect ransomware group leak site, the threat actors successfully exfiltrated 250GB of highly confidential data, including internal projects, core architectural secrets, and active API keys.

Overview of the thousands of secrets extracted from S&P Global’s infrastructure inside Hudson Rock’s Cavalier portal.

Deep dive into the S&P Global runner environments, showing GitHub tokens and ECR repository URLs exposed.
3. Cisco
The Breach: Cisco’s source code was stolen in a breach linked directly to a compromised development environment running a poisoned Trivy container. The attackers likely infiltrated critical repositories, including cisco-it-cloud-infrastructure.

How Hackers Likely Got In: Judging by the environment dumps, it appears the attackers likely scraped GitHub Personal Access Tokens (PATs) and highly sensitive API keys from the runner’s environment variables. The exposure of an Artifactory token likely allowed access to internal packages, while a Conjur API key appears to have provided a foothold into Cisco’s broader secret management infrastructure.

Cisco GitHub Actions runner environment dump showing the compromised Trivy action path and internal repository links.

Exfiltrated environment configuration from Cisco revealing highly sensitive Conjur, GitHub, and JIRA secrets.
4. European Commission
The Breach: The European Commission suffered a severe cloud breach resulting from this campaign. The compromised runner was executing a Terraform deployment for AWS infrastructure.

How Hackers Likely Got In: Telemetry indicates attackers likely obtained AWS IAM credentials directly from the environment, granting administrative cloud access. Furthermore, a hardcoded SSH private key and GitLab CI tokens appear to have been exposed, which would likely allow the threat actors to pivot laterally across the European Commission’s GitLab infrastructure.

Raw exfiltrated log from the European Commission breach highlighting exposed AWS access keys and GitLab tokens.
5. Mercor
The Breach: Mercor, a $10 billion AI startup, faced a catastrophic security incident impacting their AI annotation and RL Studio platform resulting from the LiteLLM supply chain attack.

How Hackers Likely Got In: Based on the data, it appears attackers likely exfiltrated local configuration files and runner environment variables. This would provide direct administrative access to Mercor’s AI models via Anthropic API keys, project management via Linear, and data pipelines via Datadog and Dagster.

Hudson Rock Cavalier view showing the exact compromised Mercor environment variables, including Anthropic, Linear, and Datadog API keys inside Cavalier (secrets blurred for safety).
Outcome of the Breach: The fallout for Mercor has been monumental. According to available reports, attackers moved laterally through Mercor’s systems and extracted approximately 4 Terabytes of data. This included 939 GB of proprietary source code, potential AI training methodologies, video interviews, and user database records containing the Social Security numbers and biometric data of over 40,000 contractors. Meta subsequently paused a major data contract, and multiple class-action lawsuits have been filed.

The Lapsus$ extortion group claiming to have permanently sold the entirety of Mercor’s biometric, PII, and AI training data to Chinese enterprises.
6. Telnyx
The Breach: Telecom and communications platform Telnyx was breached through their internal infrastructure via malicious Python SDK packages tied to the broader campaign.

How Hackers Likely Got In: According to the data dumps, it is assessed that attackers likely recovered Docker configuration files containing base64-encoded basic authentication credentials and GitHub PATs. This would have allowed threat actors to pull and push directly to Telnyx’s internal production and development container registries.

Hudson Rock Cavalier view displaying the exfiltrated Docker configuration and GitHub tokens from Telnyx’s environment (secrets blurred for safety).
Outcome of the Breach: On March 27, 2026, two unauthorized versions of the Telnyx Python SDK (4.87.1 and 4.87.2) were published to PyPI containing malicious credential-stealing code. Telnyx publicly confirmed the incident, clarifying that while the PyPI distribution channel was compromised, the Telnyx platform, APIs, customer data, and voice/messaging infrastructure itself were not compromised.
Click here for the original Source.
_________________________________________________________________________________________
Get your CompTIA A+, Network+ White Hat-Hacker, Certified Web Intelligence Analyst and more starting at $35 a month. Click here for more details.
