A supply-chain attack on the open-source tool LiteLLM leaked terabytes of credentials belonging to some of the world's biggest companies.
Security firms CloudSEK and Hudson Rock this week detailed how attackers compromised versions of LiteLLM, a popular open-source tool for building AI-powered software, distributed through the official Python Package Index. During a 40-minute window in March, anyone who downloaded the tainted package had their secrets siphoned off. CloudSEK says the haul included cloud keys, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials, environment variables, and AI provider keys - enough to potentially unlock systems at more than 2,500 organizations. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the companies whose credentials turned up in the exposure, and Hudson Rock says it found the data while combing through a 195TB file, though neither firm has said where that file came from.
This is what makes software supply-chain attacks so dangerous: a single 40-minute compromise of one package can ripple out to thousands of organizations that never chose to trust the attacker, only the package's maintainers. LiteLLM sits deep in AI development pipelines, so the blast radius here likely includes internal AI tooling and cloud infrastructure that companies assumed was walled off.
Two respected security firms are converging on the same finding, but the source of that 195TB file remains unexplained - which means nobody yet knows who is holding this data, or what they intend to do with it.