LiteLLM Supply Chain Attack Leaks Credentials for 2,500 Organizations
TL;DR. A supply-chain attack on LiteLLM, an open-source tool for AI development, exfiltrated terabytes of sensitive credentials from 2,500 organizations. - The attack, attributed to TeamPCP, compromised LiteLLM versions downloaded from the Python Package Index in a 40-minute window. - Exposed data included cloud keys, repository tokens, and Kubernetes secrets, affecting companies like Microsoft, Amazon, and Cisco. - Security firms CloudSEK and Hudson Rock discovered the breach, which stemmed from a prior attack on vulnerability scanner Trivy.
- A supply-chain attack targeted LiteLLM, an open-source tool for AI software development.
- Terabytes of credentials from 2,500 organizations, including major tech companies, were leaked.
- The breach occurred over a 40-minute period in March, impacting users who downloaded compromised LiteLLM versions.
- The attack, attributed to 'TeamPCP,' also compromised other software like Trivy and KICS.
Sources
- Terabytes of credentials leaked in massive supply-chain attack — arstechnica.com