CYBERSECURITYTRACKER
TRACKING4,001 stories742 vuln stories
Permanent story citation

Terabytes of credentials leaked in massive supply-chain attack

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4350

As cited

Citation snapshot as of .

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.

Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.

Source published
First seen by Cybersecurity Tracker

Source attribution