LiteLLM Supply Chain Attack Leaks Credentials for 2,500 Organizations

TL;DR. A supply-chain attack on LiteLLM, an open-source tool for AI development, exfiltrated terabytes of sensitive credentials from 2,500 organizations. - The attack, attributed to TeamPCP, compromised LiteLLM versions downloaded from the Python Package Index in a 40-minute window. - Exposed data included cloud keys, repository tokens, and Kubernetes secrets, affecting companies like Microsoft, Amazon, and Cisco. - Security firms CloudSEK and Hudson Rock discovered the breach, which stemmed from a prior attack on vulnerability scanner Trivy.

Sources

Back to QLANKR News