LiteLLM Supply Chain Exposure Check

Were you exposed in the
LiteLLM supply chain attack?

Enter your domain to check whether credentials tied to your organization appear in the exposed data. Free, and takes seconds.

Search your full domain (e.g., yourcompany.com) — not a URL or email — for the most precise match.

This tool searches Whiteintel's index of exposed secrets from the LiteLLM supply chain attack (malicious litellm 1.82.7 / 1.82.8 packages) for credentials associated with your domain — API keys, cloud credentials, and tokens.

Results are estimated based on indexed data. For the complete list of exposed secrets and a responsible, ethical disclosure, contact our team.

In short

The LiteLLM Supply Chain Exposure Check is a free tool that tells you whether credentials tied to your domain were leaked in the LiteLLM supply chain attack — the malicious litellm 1.82.7 and litellm 1.82.8 packages published to PyPI on March 24, 2026, which harvested API keys, cloud credentials, SSH keys, and Kubernetes tokens from affected environments. Enter your domain above, complete the captcha, and Whiteintel searches its index of exposed secrets for a match. Results are estimated; for the full, itemized list we provide a responsible, ethical disclosure to the verified owner.

What was the LiteLLM supply chain attack?

On March 24, 2026, two trojanized versions of the popular open-source LLM gateway LiteLLM1.82.7 and 1.82.8 — were published to the Python Package Index (PyPI). Anyone who installed or deployed those releases ran attacker-controlled code that exfiltrated secrets from the host environment. Because LiteLLM commonly sits in front of production AI infrastructure, the packages had access to exactly the credentials attackers want most: model-provider API keys, cloud access keys, SSH keys, and Kubernetes service-account tokens.

The malicious releases were live only briefly, but the blast radius is outsized: a single leaked cloud key or Kubernetes token can unlock an entire environment. For the full timeline, indicators of compromise, and affected-version details, read our LiteLLM supply chain attack advisory.

How the exposure check works

  1. 1

    Enter your domain — for example yourcompany.com. No account or email is required.

  2. 2

    Complete the captcha to confirm you're human and protect the service from abuse.

  3. 3

    Review your exposure summary — Whiteintel searches its index of secrets leaked in the LiteLLM attack and returns an estimated count of exposed files, secrets, and the types of credentials found.

  4. 4

    Rotate and request full disclosure — rotate every affected secret and contact our team for the complete, itemized list under responsible disclosure.

What kind of secrets were exposed?

The malicious LiteLLM packages targeted high-value credentials that are typically present in AI and cloud environments, including:

  • Model-provider API keys — OpenAI, Anthropic, and other LLM API keys.
  • Cloud credentials — AWS, GCP, and Azure access keys and secrets.
  • SSH keys — private keys granting server access.
  • Kubernetes tokens — service-account tokens and cluster credentials.

What to do if your domain is exposed

  • Rotate every secret that could have been present where an affected LiteLLM version ran — assume all are compromised.

  • Revoke and reissue API keys, cloud access keys, SSH keys, and Kubernetes tokens; invalidate active sessions.

  • Pin to a known-good release — remove 1.82.7/1.82.8 and pin LiteLLM to a version you trust.

  • Audit for misuse — review cloud, provider, and cluster logs for unauthorized access after March 24, 2026.

  • Get the full listcontact Whiteintel for a responsible disclosure of exactly which of your secrets were found.

Frequently asked questions

What is the LiteLLM Supply Chain Exposure Check?

The LiteLLM Supply Chain Exposure Check is a free tool from Whiteintel that searches our index of secrets leaked in the LiteLLM supply chain attack (malicious litellm 1.82.7 / 1.82.8 on PyPI) for credentials associated with your domain. You enter a domain, complete a captcha, and get an estimated exposure summary in seconds — no signup required.

How do I know if I was affected by the LiteLLM supply chain attack?

If you installed, built, or deployed litellm 1.82.7 or 1.82.8 (published to PyPI on March 24, 2026), any secret present in that environment — API keys, cloud credentials, SSH keys, or Kubernetes tokens — should be treated as compromised. Use this exposure check to see whether credentials tied to your domain already appear in leaked data.

Which LiteLLM versions were malicious?

The compromised releases are litellm 1.82.7 and 1.82.8. Remove them immediately and pin LiteLLM to a version you trust (for example, the last known-good release before the attack, or a patched release).

Is the exposure check free?

Yes. Checking your domain is completely free and requires no account. The results shown are estimated from Whiteintel's indexed data; for the full, itemized list of exposed secrets we provide a responsible, ethical disclosure to the verified owner — contact us.

Does "no exposure found" mean I'm safe?

Not necessarily. It means we haven't indexed leaked credentials for your domain yet — new data surfaces continuously. If you ran an affected LiteLLM version, you should still rotate every secret in that environment and re-check periodically.

What should I do if my domain is exposed?

Rotate and revoke all potentially affected secrets, reissue API keys and cloud credentials, invalidate SSH keys and Kubernetes tokens, audit access logs for misuse after March 24, 2026, and remove the malicious LiteLLM versions. Then contact Whiteintel for the complete list of what leaked.

How current is the exposure data?

Whiteintel continuously indexes exposed secrets and dark-web data, so results reflect the latest information we have. Because new leaks appear over time, we recommend re-checking your domain periodically and monitoring continuously.

Rotating isn't enough — find out what already leaked

Whiteintel monitors the dark web for exposed credentials, infostealer logs, and leaked secrets so you can act before attackers do.

Related reading

Last updated: August 21, 2026 · Whiteintel threat research

Get Started for Free

Experience Whiteintel, trusted by enterprises, MSSPs, and top researchers for real-time exposure monitoring.