Terabytes of credentials leaked in massive supply-chain attack

A massive supply-chain attack on LiteLLM and related DevOps tools exposed terabytes of credentials from over 2,500 organizations—including Fortune 500 companies like Microsoft, Amazon, Cisco, and Salesforce—compromising 434,000 CI/CD pipelines in just a 40-minute window. The breach underscores critical vulnerabilities in organizations' rush to integrate AI into development workflows without adequate security controls, exposing active database passwords, cloud credentials, and API keys across enterprise infrastructure. IT leaders must immediately audit and rotate all credentials for affected systems while reassessing their third-party dependency management and DevOps security posture to prevent similar cascading attacks.

Dan GoodinArs Technica2 min read
Read full article
Terabytes of credentials leaked in massive supply-chain attack
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations. 40 minutes is all it takes The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.Read full article Comments