A massive supply-chain attack has exposed terabytes of sensitive credentials belonging to some of the world’s largest organizations. The target was LiteLLM, an open-source tool used to streamline AI-driven software development. Affected entities include industry giants such as Microsoft, Amazon, Cisco, Samsung, and Salesforce.

Anatomy of a High-Speed Breach

According to reports from security firms CloudSEK and Hudson Rock, the data was exfiltrated during a brief 40-minute window in March. During this time, victims downloaded compromised versions of LiteLLM from the official Python Package Index (PyPI) repository. Researchers analyzed a 195TB file containing cloud keys, SSH tokens, Kubernetes secrets, and AI provider credentials.

The compromise of LiteLLM stemmed from an upstream supply-chain attack on the widely used vulnerability scanner Trivy. Other infected software includes KICS and the Telnyx Python SDK. TeamPCP, a gang primarily composed of teenagers, claimed responsibility for the attack—a claim largely corroborated by security researchers.

Corporate Security Failures

Independent researcher Kevin Beaumont confirmed the legitimacy of the data, noting that the corporate rush to integrate AI has led to significant lapses in DevOps security. In total, credentials for approximately 434,000 CI/CD software pipelines were exposed.

A concerning aspect of the discovery is the apparent lack of urgency from some victims. Beaumont reported that one major U.S. tech company claimed to have rotated its secrets, yet a subsequent test of the leaked credentials revealed that nearly all of them were still active and functional.

Recommendations for Mitigation

Security experts are urging all organizations that utilized LiteLLM versions 1.82.7 and 1.82.8 to immediately rotate all credentials. Hudson Rock advises a thorough audit of environments for these specific versions and the implementation of aggressive credential revocation for any secret accessible to the LiteLLM environment.