tech
Terabytes of credentials leaked in massive supply-chain attack
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

TL;DR
- Terabytes of credentials, including cloud keys, repository tokens, and AI provider keys, were exposed in a supply-chain attack on the open-source tool LiteLLM.
- Major organizations like Microsoft, Amazon, Cisco, Samsung, and Salesforce were among the entities affected.
- The attack exploited compromised versions of LiteLLM downloaded from the Python Package Index, which were infected via a previous attack on the vulnerability scanner Trivy.
- The compromised code scraped memory and exfiltrated sensitive data, including credentials for over 434,000 CI/CD software pipelines.
- Security firms CloudSEK and Hudson Rock discovered the breach, attributing it to the group TeamPCP.
- Organizations using affected versions of LiteLLM are urged to rotate all credentials immediately.