[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-litellm-supply-chain-breach-still-has-working-credentials":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},5769,"litellm-supply-chain-breach-still-has-working-credentials","LiteLLM Supply-Chain Breach Still Has Working Credentials","Nearly five months after hackers hit an open-source tool used by LiteLLM, researcher Kevin Beaumont found some of the stolen keys are still valid.","Credentials stolen in a supply-chain attack on a security tool are still working, five months after the breach was discovered.\n\nSecurity researchers at CloudSEK and Hudson Rock say a financially motivated group called TeamPCP compromised a build of Trivy, an open-source vulnerability scanner made by Aqua Security. LiteLLM, a gateway that translates calls to more than 100 AI models into one API format, automatically pulled in the poisoned Trivy package without verifying it. That gave the attackers server-administrator access and let them install a credential stealer. The haul included cloud keys, SSH keys, Kubernetes tokens, and AI provider keys tied to more than 2,500 organizations, among them Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group.\n\nThis is not one company's data spilling out. It is a shared set of keys to hundreds of companies' cloud infrastructure, CI\u002FCD pipelines, and code repositories, all harvested through a single trusted dependency. Independent researcher Kevin Beaumont tested some of the leaked keys and found they still worked, even though the affected organization said it had rotated them.\n\nRotating a key on paper and rotating it in practice are apparently two different chores.","[\"supply-chain-attack\",\"litellm\",\"credential-theft\",\"open-source-security\"]","2026-08-21T03:00:00.000Z","2026-08-21T04:04:37.413Z","2026-08-21T04:04:49.339Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek claims 'many' organizations still have exposed credentials, but the body and source only say Kevin Beaumont found 'some' keys still valid — align the dek's magnitude with the body's actual claim.","resolved","security",[32,33,34,35],"supply-chain-attack","litellm","credential-theft","open-source-security",[37],{"name":38,"url":39},"TechRadar","https:\u002F\u002Fwww.techradar.com\u002Fpro\u002Fsecurity\u002Fmassive-supply-chain-attack-sees-terabytes-of-data-belonging-to-some-of-the-worlds-biggest-and-most-sensitive-organizations-leaked-online",0,{"sections":42},[43,48,51,56,61,66,71,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3300,"2026-08-21T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",449,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",211,"2026-08-20T10:47:43.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",141,"2026-08-20T11:20:00.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",91,"2026-08-20T10:01:48.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",48,"2026-08-20T18:34:26.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]