As cited
Citation snapshot as of .
breaches incidents
Terabytes of credentials leaked in massive supply-chain attack
A supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials belonging to over 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The compromised versions were downloaded from the official Python Package Index repository during a 40-minute window in March, leaking cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider credentials that could grant attackers broad access to victim infrastructure.
Why it matters: Development teams using LiteLLM need to immediately audit which versions they deployed in March, rotate all exposed credentials, and review access logs for unauthorized activity, as attackers may have obtained keys to critical cloud and infrastructure systems across your organization.
- Source published
- First seen by Cybersecurity Tracker