Terabytes of credentials leaked in massive supply-chain attack
Security firms CloudSEK and Hudson Rock have revealed a massive supply-chain attack exposing terabytes of credentials. The attack targeted LiteLLM, an open-source tool used for AI-driven software development.

Terabytes of user credentials and access secrets, including data from major international organizations, have been exposed in a supply-chain attack. The incident targeted LiteLLM, an open-source tool used to streamline AI-driven software development.
Security firms CloudSEK and Hudson Rock published their findings on Tuesday and Wednesday. According to the reports, the exposed data, such as cloud keys, repository tokens, SSH keys, and environment variables, could grant attackers access to over 2,500 organizations.
The compromised credentials were extracted during a 40-minute window in March from compromised versions of LiteLLM downloaded from the Python Package Index repository. Hudson Rock discovered the breach after analyzing a 195TB file. Neither security firm has identified the origin of the leaked information.
The scale of the attack and the exposure of data from entities like Microsoft, Amazon, Cisco, Samsung, and Salesforce highlight the vulnerabilities within software supply chains.