📣 Send us your press release
Site updates every 15 minutes
Technology

Terabytes of credentials leaked in massive supply-chain attack

Security firms CloudSEK and Hudson Rock have revealed a massive supply-chain attack exposing terabytes of credentials. The attack targeted LiteLLM, an open-source tool used for AI-driven software development.

12 August 2026
Terabytes of credentials leaked in massive supply-chain attack

Terabytes of user credentials and access secrets, including data from major international organizations, have been exposed in a supply-chain attack. The incident targeted LiteLLM, an open-source tool used to streamline AI-driven software development.

Security firms CloudSEK and Hudson Rock published their findings on Tuesday and Wednesday. According to the reports, the exposed data, such as cloud keys, repository tokens, SSH keys, and environment variables, could grant attackers access to over 2,500 organizations.

The compromised credentials were extracted during a 40-minute window in March from compromised versions of LiteLLM downloaded from the Python Package Index repository. Hudson Rock discovered the breach after analyzing a 195TB file. Neither security firm has identified the origin of the leaked information.

The scale of the attack and the exposure of data from entities like Microsoft, Amazon, Cisco, Samsung, and Salesforce highlight the vulnerabilities within software supply chains.

Original source: arstechnica.com