Terabytes of credentials leaked in massive supply-chain attack

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Terabytes of credentials from over 2,500 organizations, including Microsoft, Amazon, Cisco, Samsung, and Salesforce, were exposed through a supply-chain attack on LiteLLM, an open source AI development tool. Security firms CloudSEK and Hudson Rock found cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider keys in a 195TB file, affecting roughly 434,000 CI/CD pipelines. The compromised LiteLLM versions were live on PyPI for only a 40-minute window in March, and the breach traces back to an earlier compromise of the Trivy vulnerability scanner, which also infected KICS and the Telnyx Python SDK. A group calling itself TeamPCP, described as largely made up of teenagers, has claimed responsibility, with researchers largely corroborating the claim.

3m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoWhat Happens to the Developers When AI Can Code? | Ars Frontiers

Questions this post answers

What happened in the LiteLLM supply chain attack?

Attackers compromised LiteLLM, an open source AI development tool, on PyPI for a 40-minute window in March, injecting code that scraped machine memory and exfiltrated credentials. Security firms CloudSEK and Hudson Rock found cloud keys, SSH keys, Kubernetes secrets, and AI provider keys from over 2,500 organizations and roughly 434,000 CI/CD pipelines in a 195TB data dump. Teams tracking supply-chain risk in their dependencies can follow breaking security incidents like this on daily.dev.

How did the LiteLLM compromise on PyPI happen in the first place?

The LiteLLM breach traces back to an earlier supply-chain attack that infected the widely used Trivy vulnerability scanner; the same campaign also compromised KICS and the Telnyx Python SDK. A group called TeamPCP, described as largely composed of teenagers, has claimed credit, and researchers have largely corroborated that claim. Developers auditing their dependency chains for compromised tooling can track fast-moving supply-chain stories on daily.dev.

How many organizations and CI/CD pipelines were affected by the LiteLLM credential leak?

Over 2,500 organizations and approximately 434,000 CI/CD pipelines had credentials exposed after running compromised versions of LiteLLM during the 40-minute attack window. Affected entities include Microsoft, Amazon, Cisco, Samsung, and Salesforce, though researchers had trouble attributing some credentials to their true owning organizations. daily.dev helps engineers stay ahead of large-scale credential exposure affecting their own pipelines.

2 Impressions