Supply-Chain Attack on LiteLLM Leaks Terabytes of Credentials

A supply-chain attack on LiteLLM, an open-source tool for AI software development, exposed terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported that the stolen data included cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials, potentially compromising more than 2,500 organizations.

The credentials were harvested during a 40-minute window in March after victims installed compromised LiteLLM versions from the official Python Package Index repository. Hudson Rock said it analyzed a 195TB file, but neither firm identified the source of the breach.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleByteDance Develops Huge AI Model to Challenge Anthropic
Start typing to search