Massive Supply-Chain Attack on LiteLLM Exposes Terabytes of Credentials

A supply-chain attack on LiteLLM, an open-source tool used to streamline AI software development, exposed terabytes of credentials belonging to major organizations, including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported the breach, with Hudson Rock analyzing a 195TB file containing the stolen data.

The credentials were extracted during a 40-minute window in March after victims downloaded compromised LiteLLM versions from the Python Package Index. The exposed data includes cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider keys, potentially giving attackers access to more than 2,500 organizations.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers
Start typing to search