All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Massive Supply-Chain Attack Exposes Terabytes of Credentials via LiteLLM

Created at 12 Aug · 9:51 PM1 source↑ Market-relevant
IN SHORT

A supply-chain attack on the open-source AI tool LiteLLM has exposed terabytes of credentials, including cloud keys, SSH keys, and repository tokens, affecting thousands of organizations. The breach, attributed to a group known as TeamPCP, occurred over a 40-minute window in March.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

40 minuteswindow for credential extraction
195TBfile analyzed by Hudson Rock
2,500+organizations potentially affected
434,000CI/CD software pipelines exposed

Who's Involved

LiteLLM
open source tool for AI development, victim of supply-chain attack
CloudSEK
security firm that reported the breach
Hudson Rock
security firm that reported the breach
Microsoft
organization whose credentials were exposed
Amazon
organization whose credentials were exposed
Cisco
organization whose credentials were exposed
Samsung
organization whose credentials were exposed
Salesforce
organization whose credentials were exposed
TeamPCP
group claiming responsibility for the attack
Kevin Beaumont
independent security researcher who confirmed data legitimacy
Massive Supply-Chain Attack Exposes Terabytes of Credentials via LiteLLM

↳ Why This Matters

This incident highlights critical vulnerabilities in software supply chains and the security practices surrounding AI development tools, potentially exposing thousands of organizations to further cyber threats and data breaches.

Key facts

  • Terabytes of credentials, including cloud keys, SSH keys, and repository tokens, were exposed in a supply-chain attack on LiteLLM.
  • Major organizations such as Microsoft, Amazon, Cisco, Samsung, and Salesforce were among those affected.
  • The attack occurred over a 40-minute window in March when users downloaded compromised versions of LiteLLM.
  • The breach is linked to a prior attack that infected the vulnerability scanner Trivy.
  • The group TeamPCP has claimed responsibility for the attack.
  • Approximately 434,000 CI/CD software pipelines had credentials exposed.

A significant supply-chain attack has resulted in the exposure of terabytes of sensitive credentials, impacting numerous major organizations globally. The breach targeted LiteLLM, an open-source tool used to streamline AI development, with compromised versions downloaded from the Python Package Index repository.

Security firms CloudSEK and Hudson Rock revealed the incident, stating that cloud keys, repository tokens, SSH keys, and other secrets were exfiltrated. These credentials could grant attackers access to over 2,500 organizations. The attack occurred over a brief 40-minute period in March, exploiting vulnerabilities introduced through a previous supply-chain attack that infected the widely used vulnerability scanner Trivy, as well as KICS and the Telnyx Python SDK.

The hacking group TeamPCP has claimed responsibility for the breach, a claim largely corroborated by researchers. Independent security researcher Kevin Beaumont confirmed the authenticity of the leaked data, highlighting the significant volume of sensitive content. He noted that the breach underscores poor AI security practices and DevOps vulnerabilities, rather than AI itself being the threat.

The compromised software packages contained code designed to access machine memory, scrape its contents, and transmit the data to an attacker-controlled channel. This resulted in the exposure of credentials for approximately 434,000 CI/CD software pipelines. In some instances, identifying the exact organizations linked to the credentials proved challenging, with one email domain leading to a subsidiary rather than the parent company.

Frequently asked questions

LiteLLM is an open-source tool designed to simplify the development of AI-driven software, allowing developers to interact with various AI models through a unified interface.

Compromised versions of LiteLLM, downloaded from its official repository, contained malicious code that scraped credentials from infected machines and sent them to attackers.

The hacking group TeamPCP has claimed responsibility for the attack, and researchers have largely corroborated this claim.

Exposed credentials include cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys.

What Happens Next

01Organizations are expected to revoke and rotate compromised credentials.
02Further investigation into the full scope of the breach and attribution is likely.
03Security researchers will continue to analyze the leaked data for additional impacts.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A supply-chain attack on the AI tool LiteLLM has exposed terabytes of credentials.
Security firms CloudSEK and Hudson Rock reported the breach, detailing exposed cloud keys, repository tokens, and SSH keys.
The compromised versions of LiteLLM were downloaded from the Python Package Index repository.
The attack, which lasted 40 minutes in March, infected machines that ran the compromised software.
The LiteLLM compromise stemmed from a prior attack that infected vulnerability scanner Trivy and other software.
The group TeamPCP has claimed responsibility for the attack.
Independent security researcher Kevin Beaumont confirmed the legitimacy of the data, noting its sensitive nature.
Compromised software accessed machine memory, scraped contents, and exfiltrated data through an attacker-controlled channel.

Sources

T1
Terabytes of credentials leaked in massive supply-chain attackvar abtest_2167268 = new ABTest(2167268, 'impression');Ars Technica

Related Stories

AI Model 'Inner Thoughts' Exposed, Revealing API Keys and Passwords
12 Aug · 8:35 PM
AI Used to Discover Critical Zoom Vulnerabilities in One Day
12 Aug · 1:46 PM
New font aims to poison AI training data by altering web page text
12 Aug · 10:06 PM
AI adoption leaves accountancy firms vulnerable to cyberattacks
12 Aug · 2:51 PM
DEF CON attendees suspected of spoofing Delta flight Wi-Fi
12 Aug · 12:15 AM