Massive LiteLLM Supply-Chain Attack Leaks Terabytes of Corporate Credentials

Terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce were exposed in a supply-chain attack on LiteLLM, an open-source AI development tool. Security firms CloudSEK and Hudson Rock reported the breach, saying the stolen data included cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could compromise more than 2,500 organizations.

The credentials were harvested during a 40-minute window in March when victims downloaded compromised LiteLLM packages from the official Python Package Index repository. Hudson Rock identified the leak after analyzing a 195TB file; neither firm has identified the source of the data.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleCloudflare open-sources its AI app-building platform for non-coders
Start typing to search