Terabytes of credentials leaked in massive supply-chain attack

← Back to the feed

Terabytes of credentials leaked in massive supply-chain attack

Ars Technica · 2 hours ago

A supply-chain attack on the open-source AI development tool LiteLLM exposed terabytes of sensitive credentials from thousands of organisations, including major technology, industrial and financial firms. The incident matters because the stolen material could enable unauthorised access to cloud systems, code repositories, software pipelines and AI services.

The compromised LiteLLM releases were available through PyPI for about 40 minutes in March and contained code that scraped infected machines’ memory and sent data to attacker-controlled infrastructure. Security firms CloudSEK and Hudson Rock said roughly 434,000 CI/CD pipelines had credentials exposed, potentially affecting more than 2,500 organisations; the data reportedly included cloud keys, SSH keys, Kubernetes secrets and application tokens. The attack was linked to an earlier compromise of the Trivy vulnerability scanner and was claimed by TeamPCP, a group reportedly including teenagers.

  • Compromised LiteLLM packages exposed terabytes of sensitive credentials.
  • Around 434,000 software pipelines may have leaked secrets.
  • Major firms were reportedly among affected organisations.

AI Technology

Read the full article at the source →