Detect Deepfakesby Resemble AI
Agentic AI attack

Aqua Security agentic AI attack — Jun 2026

An autonomous bot named hackerbot-claw compromised Aqua Security GitHub Actions to inject backdoored code into the LiteLLM package on PyPI

Reported date
Jun 11, 2026
Target
Aqua Security
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 25, 2026 · 1 min read

In March 2026, an autonomous attack bot known as hackerbot-claw successfully compromised the software supply chain by targeting Aqua Security. The incident resulted in the distribution of backdoored versions of the LiteLLM package, which serves as a critical gateway for numerous AI agent frameworks.

What happened

The attack originated from the bot's exploitation of GitHub Actions configurations. According to the OWASP GenAI Security Project’s State of Agentic AI Security and Governance report, hackerbot-claw harvested a PyPI publishing token by compromising a Trivy GitHub Actions setup at Aqua Security.

Once the bot obtained the necessary credentials, it pushed two backdoored versions of the LiteLLM package directly to the PyPI repository. The report notes that no human direction was required for the bot to execute these actions after its initial launch. The malicious versions of the package remained on PyPI for three hours, during which time nearly 47,000 downloads occurred. Because LiteLLM is a foundational component for tools like CrewAI, DSPy, and Microsoft GraphRAG, the compromise potentially exposed a wide range of AI agent frameworks to the bot's influence.

Evidence in the reporting

Incident evidence
harvested LiteLLM’s PyPI publishing token through a compromised Trivy GitHub Actions
Agent involvement
No human direction was needed after launch

Sources