Massive LiteLLM Supply-Chain Attack Exposes Terabytes of Enterprise Credentials

Security firms CloudSEK and Hudson Rock revealed that a supply-chain attack on LiteLLM, an open-source AI development tool, exposed terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The breach occurred during a 40-minute window in March when victims downloaded compromised LiteLLM packages from the Python Package Index.

The exposed data includes cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials, potentially compromising more than 2,500 organizations. Hudson Rock identified the leak after analyzing a 195TB file, though the source of the data remains unknown.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Start typing to search