A significant supply-chain attack on LiteLLM, an open-source tool for AI-driven software development, has resulted in the exposure of terabytes of credentials from numerous organizations. Entities affected include Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported the breach, revealing that sensitive information such as cloud keys, repository tokens, SSH keys, and AI provider keys were compromised, potentially affecting over 2,500 organizations. The credentials were extracted during a 40-minute period in March when users downloaded compromised versions of LiteLLM from the official Python Package Index repository. Hudson Rock discovered the breach after analyzing a 195TB file, but the source of the information has not been disclosed.
✓ No loaded language, vague sourcing, or framing detected.
Credentials Exposed in Supply-Chain Attack on LiteLLM
A supply-chain attack on LiteLLM has led to the exposure of terabytes of credentials from major organizations, including Microsoft and Amazon. Security firms CloudSEK and Hudson Rock reported that the breach could impact over 2,500 entities, with sensitive information compromised during a brief window in March.
No note attached
on this article.
Original vs. Neutral
Terabytes of credentials leaked in massive supply-chain attack
Credentials Exposed in Supply-Chain Attack on LiteLLM