As cited
Copy frozen at (site build).
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.
Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.
Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
A supply-chain compromise of the open-source LiteLLM library exposed terabytes of credentials from thousands of organizations, including major tech firms. Security researchers CloudSEK and Hudson Rock identified the leak after analyzing a 195-TB file and tracing the theft to a 40-minute window in March when malicious versions were downloaded from PyPI.
Why it matters: Organizations that used LiteLLM from PyPI in March must rotate all exposed credentials and audit access to avoid compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
A supply-chain compromise of the open-source LiteLLM library exposed terabytes of credentials from thousands of organizations, including major tech firms. Security researchers CloudSEK and Hudson Rock identified the leak after analyzing a 195-TB file and tracing the theft to a 40-minute window in March when malicious versions were downloaded from PyPI.
Why it matters: Organizations that used LiteLLM from PyPI in March must rotate all exposed credentials and audit access to avoid compromise.
- Source published
- First seen by Cybersecurity Tracker