Massive Supply-Chain Attack on LiteLLM Leaks Terabytes of Enterprise Credentials

A supply-chain attack on LiteLLM, an open-source AI development tool, exposed terabytes of credentials belonging to organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported the breach, with CloudSEK finding keys and secrets that could allow access to more than 2,500 organizations.

The credentials were harvested during a 40-minute window in March when victims downloaded compromised LiteLLM packages from PyPI. Hudson Rock analyzed a 195TB file containing the data, but neither firm identified the source of the breach.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleMeta reboots its AI strategy with new open-weight models and a Zuckerberg manifesto
Start typing to search