| 1. Claude Opus 5 (High) |
| 2. Claude Opus 5 (Max) |
| 3. Claude Fable 5 (High) |
| 4. GPT 5.6 Sol (xHigh) |
| 5. Kimi K3 (Max) |
The BriefTwo tampered versions of a tool called LiteLLM, which a lot of companies use to route requests between different AI providers, were published to the main Python software repository in March and sat there for about 40 minutes before being pulled. That was long enough. Anything that installed during the window handed over its cloud keys, and the researchers who pieced it together count more than 2,500 organizations and 434,000 automated build pipelines, with Amazon, Samsung, Cisco, Salesforce and Siemens among the confirmed names. The part worth sitting with is not the size, it is that this happened in March and only surfaced this week, so the window between being compromised and knowing about it was four months.
Level UpThere is a free lookup for this one, so the first step takes about a minute: put your own domains through CloudSEK's exposure checker and see whether you appear in the reconstructed data. Then do the boring part, which is the part that actually prevents the next one. Go look at how your builds install dependencies. If anything says 'take the latest version', that is the door this walked through, because a poisoned release published for 40 minutes is only dangerous to a system that will accept whatever is newest. Pinning to an exact version and hash means a tampered release cannot install itself, and it turns a four-month blind spot into a decision somebody has to make on purpose. CloudSEK: check whether your organization is exposed