tech

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Terabytes of credentials leaked in massive supply-chain attack

TL;DR

  • Terabytes of credentials, including cloud keys, repository tokens, and AI provider keys, were exposed in a supply-chain attack on the open-source tool LiteLLM.
  • Major organizations like Microsoft, Amazon, Cisco, Samsung, and Salesforce were among the entities affected.
  • The attack exploited compromised versions of LiteLLM downloaded from the Python Package Index, which were infected via a previous attack on the vulnerability scanner Trivy.
  • The compromised code scraped memory and exfiltrated sensitive data, including credentials for over 434,000 CI/CD software pipelines.
  • Security firms CloudSEK and Hudson Rock discovered the breach, attributing it to the group TeamPCP.
  • Organizations using affected versions of LiteLLM are urged to rotate all credentials immediately.