Smart news for curious minds.

Nerd News Network
Technology

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

A cartoon man runs across a white field of ones and zeroes.
Image: Ars Technica
Share

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

The short version

  • Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development.
  • Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
  • The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock.

What happened

CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations. The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository.

Why it matters

Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained.

Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.

Share