A supply-chain attack on the open-source AI development tool LiteLLM exposed terabytes of credentials from over 2,500 organizations, including major companies like Microsoft, Amazon, Cisco, and Salesforce. Attackers exploited compromised versions of LiteLLM available on the Python Package Index during a 40-minute window in March to scrape sensitive secrets such as cloud keys, SSH keys, and CI/CD pipeline credentials, impacting around 434,000 software pipelines. Security firms CloudSEK and Hudson Rock urge affected organizations to immediately rotate all exposed credentials and audit their environments to mitigate the widespread risk from this incident.
Terabytes of Credentials Leaked in Massive Supply-Chain Attack

