Artificial IntelligenceCybersecurityNewswireTechnologyWhat's Buzzing

LiteLLM supply chain attack exposes 153GB of stolen credentials

▼ Summary

– A 153GB archive from the LiteLLM supply chain attack contains credentials and sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce, with 118,829 CI runner dumps attributed to 2,488 companies.
– The breach originated from a compromised version of the Trivy scanner, installed via LiteLLM’s build pipeline, which stole PyPI publishing tokens used to publish malicious LiteLLM versions 1.82.7 and 1.82.8 on March 24.
– Hudson Rock is conducting an ethical disclosure effort to help organizations respond before the data leaks publicly, but notes many files lack clear ownership markers, so some affected organizations may not know they are exposed.
– Exposed data includes AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys, with victims spanning NVIDIA, Volkswagen, Microsoft, FedEx, and others.
– Experts urge organizations to audit for the malicious LiteLLM versions, rotate all cloud IAM keys and access tokens, and review audit logs for anomalies, though some victims have downplayed the risk despite verified active credentials.

A staggering 153GB trove of stolen credentials and sensitive corporate data, harvested during the recent LiteLLM supply chain attack, has been obtained and analyzed by threat intelligence firm Hudson Rock. The archive, which contains 433,909 files, exposes secrets linked to thousands of major organizations, including AWS, Samsung, Cisco, and Salesforce, and has triggered a global ethical disclosure campaign to help victims before the data is weaponized.

Hudson Rock has attributed 118,829 CI runner dumps to 2,488 distinct corporate domains. “We are leveraging this data for a global ethical disclosure effort,” said Alon Gal, Hudson Rock’s co-founder and CTO. “We see this as an opportunity to help organizations respond proactively before threat actors weaponize the data publicly.”

The attack chain is a textbook example of modern supply chain fragility. LiteLLM, a popular open-source proxy gateway used by developers to route requests to various AI models, was compromised indirectly. The breach originated with an earlier takeover of Trivy, a widely used open-source vulnerability scanner. On March 19, 2026, a cybercriminal group known as TeamPCP, which emerged in late 2025, used stolen credentials to publish a malicious version of Trivy. Because LiteLLM’s build pipeline automatically installed this scanner, the poisoned tool gained read access to the runner environment, allowing attackers to exfiltrate the project’s PyPI publishing tokens.

Armed with those tokens, TeamPCP published two backdoored LiteLLM releases, versions 1.82.7 and 1.82.8, to the Python Package Index on March 24. “The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Gal explained. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested.”

The leaked dataset is a goldmine for cybercriminals, containing credentials tied to a who’s who of the corporate world: NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte, and Siemens. Screenshots accompanying the research reveal AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys captured during pipeline execution.

Independent analysis from CloudSEK, working from a separate dataset of roughly 434,000 stolen files, puts the number of exposed organizations at nearly 2,500, though the firm emphasizes these figures indicate exposure, not necessarily confirmed breaches. Security researcher Kevin Beaumont independently verified the data’s authenticity. “I’ve confirmed the data is legit by the way, multiple victim orgs,” he said. “It contains a significant volume of sensitive content at orgs. It’s a massive supply chain breach due to poor AI security, not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security.”

Accurately identifying victims within the 153GB database is a complex challenge. “Identifying the victims within this 153GB database presents a unique threat intelligence challenge. Accurate attribution requires looking past the surface level to analyze the actual infrastructure boundaries,” Hudson Rock noted. In one instance, a leaked pipeline was initially linked to a committer email at SiriusXM, but deeper infrastructure markers, including a self-hosted GitLab instance at gitlab.adswizz.com, pointed to AdsWizz, a SiriusXM subsidiary. Hudson Rock stressed that correct identification depends on hard infrastructure markers rather than simple committer emails.

A significant portion of the dumped files lacks clear ownership. Some contain database passwords, third-party API keys, and cloud credentials with no company email, custom domain, or internal server name to identify their origin. This means many organizations may have exposed credentials in the dataset without any awareness of their involvement.

Hudson Rock is now urging any organization using AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to take immediate action. They recommend auditing environments for LiteLLM versions 1.82.7 and 1.82.8, treating any secrets accessible to the LiteLLM environment as compromised, rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity dating back to March 24, and checking for unauthorized .pth files or suspicious systemd services.

“While we cannot disclose how we obtained this data, it is not leaked anywhere at the moment and is not circulating widely,” Gal added. “This makes it a critical window of opportunity for companies to rotate keys and secrets before it eventually leaks, as is the natural cycle of a breach.”

Despite the severity, some organizations appear to be downplaying the risk. Beaumont described one troubling interaction: “These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.”

The sheer scale of this incident signals a paradigm shift for cybersecurity response. “This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry,” Gal concluded.

(Source: Help Net Security)

Topics

Supply Chain Attacks 98% credential theft 95% open source security 92% ai infrastructure 90% ci/cd pipeline risks 89% incident response 87% data breach disclosure 85% threat intelligence 83% malicious package publication 80% cloud security 78%
Show More