Key facts
- Terabytes of credentials, including cloud keys, SSH keys, and repository tokens, were exposed in a supply-chain attack on LiteLLM.
- Major organizations such as Microsoft, Amazon, Cisco, Samsung, and Salesforce were among those affected.
- The attack occurred over a 40-minute window in March when users downloaded compromised versions of LiteLLM.
- The breach is linked to a prior attack that infected the vulnerability scanner Trivy.
- The group TeamPCP has claimed responsibility for the attack.
- Approximately 434,000 CI/CD software pipelines had credentials exposed.
A significant supply-chain attack has resulted in the exposure of terabytes of sensitive credentials, impacting numerous major organizations globally. The breach targeted LiteLLM, an open-source tool used to streamline AI development, with compromised versions downloaded from the Python Package Index repository.
Security firms CloudSEK and Hudson Rock revealed the incident, stating that cloud keys, repository tokens, SSH keys, and other secrets were exfiltrated. These credentials could grant attackers access to over 2,500 organizations. The attack occurred over a brief 40-minute period in March, exploiting vulnerabilities introduced through a previous supply-chain attack that infected the widely used vulnerability scanner Trivy, as well as KICS and the Telnyx Python SDK.
The hacking group TeamPCP has claimed responsibility for the breach, a claim largely corroborated by researchers. Independent security researcher Kevin Beaumont confirmed the authenticity of the leaked data, highlighting the significant volume of sensitive content. He noted that the breach underscores poor AI security practices and DevOps vulnerabilities, rather than AI itself being the threat.
The compromised software packages contained code designed to access machine memory, scrape its contents, and transmit the data to an attacker-controlled channel. This resulted in the exposure of credentials for approximately 434,000 CI/CD software pipelines. In some instances, identifying the exact organizations linked to the credentials proved challenging, with one email domain leading to a subsidiary rather than the parent company.
