Massive Supply-Chain Attack on LiteLLM Leaks Terabytes of Credentials

A supply-chain attack on LiteLLM, an open-source tool used to streamline AI development, exposed credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported that attackers stole cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials, potentially compromising access to more than 2,500 organizations.

The breach occurred during a 40-minute window in March when victims downloaded compromised LiteLLM versions from the official Python Package Index repository. Hudson Rock said it uncovered the data after analyzing a 195TB file, though neither firm identified the source of the leaked information.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleOpenAI’s Expensive Smart Speaker Will Use Moving Parts to Feel “More Alive”
Start typing to search