August 13, 2026 · 17 min read
LiteLLM supply-chain leak: how I checked my own home gateway before the news cycle caught up
A 40-minute poisoned-publish window on PyPI in March turned LiteLLM into the largest AI supply-chain leak of 2026. 195 TB of credentials, 2,500+ orgs, 434,000 CI/CD pipelines. I run LiteLLM at home. Here is the audit I ran this morning, what the Postgres logs actually showed, and the call I made on whether to rotate six provider keys.
Read more →