Terabytes of credentials leaked in massive supply-chain attack
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
In a massive supply-chain attack, terabytes of sensitive credentials have been exposed, affecting numerous prominent organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. These credentials, which include cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys, were extracted during a 40-minute window in March when victims used compromised versions of LiteLLM, an open-source AI-driven software development tool.
The breach was discovered by security firms CloudSEK and Hudson Rock, who analyzed a 195TB file obtained from the Python Package Index repository. The source of the information remains unidentified.
Brief written by urgent.news from Ars Technica's own syndicated text. Machine-written — may contain errors; check the original before relying on it.