Massive LiteLLM Supply-Chain Attack Leaks Terabytes of Corporate Credentials

A supply-chain attack on LiteLLM, an open-source AI development tool, exposed terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported the breach, noting that the stolen data includes cloud keys, repository tokens, SSH keys, and other secrets affecting over 2,500 companies.

The credentials were harvested during a 40-minute window in March from compromised LiteLLM versions downloaded via the Python Package Index, with Hudson Rock analyzing a 195TB file. The source of the leak has not been identified.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers
Start typing to search