CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Terabytes of credentials leaked in massive supply-chain attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4350

As cited

Copy frozen at (site build).

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.

Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.

Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain compromise of the open-source LiteLLM library exposed terabytes of credentials from thousands of organizations, including major tech firms. Security researchers CloudSEK and Hudson Rock identified the leak after analyzing a 195-TB file and tracing the theft to a 40-minute window in March when malicious versions were downloaded from PyPI.

Why it matters: Organizations that used LiteLLM from PyPI in March must rotate all exposed credentials and audit access to avoid compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain compromise of the open-source LiteLLM library exposed terabytes of credentials from thousands of organizations, including major tech firms. Security researchers CloudSEK and Hudson Rock identified the leak after analyzing a 195-TB file and tracing the theft to a 40-minute window in March when malicious versions were downloaded from PyPI.

Why it matters: Organizations that used LiteLLM from PyPI in March must rotate all exposed credentials and audit access to avoid compromise.

VendorsAmazon Web ServicesCiscoKubernetesMicrosoftSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary