Massive LiteLLM Supply-Chain Attack Leaks Terabytes of Corporate Credentials

Terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce were exposed in a supply-chain attack on LiteLLM, an open-source AI development tool. Security firms CloudSEK and Hudson Rock reported the breach, saying the stolen data included cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could compromise more than 2,500 organizations.

The credentials were harvested during a 40-minute window in March when victims downloaded compromised LiteLLM packages from the official Python Package Index repository. Hudson Rock identified the leak after analyzing a 195TB file; neither firm has identified the source of the data.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers→
Start typing to search