344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics141
Photography & Imaging156
Design & Creative170
Customer Support131
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Security firms say hacked LiteLLM downloads leaked cloud keys and passwords from about 2,500 organizations, including many large companies.
In short: A hacked version of the LiteLLM software briefly leaked a huge amount of passwords and access keys from thousands of organizations.
Security researchers say terabytes of credentials were exposed in a supply chain attack involving LiteLLM, an open source tool used in AI-related software work. A supply chain attack is when criminals tamper with a trusted tool that many people download, like poisoning a common ingredient used in many meals.
Two security firms, CloudSEK and Hudson Rock, reported that compromised versions of LiteLLM were available for about 40 minutes in March through the Python Package Index, a common download site for Python software. During that window, the infected software allegedly pulled secrets out of computers’ memory and sent them to an attacker-controlled location.
CloudSEK said the leaked material includes cloud keys, repository tokens, SSH keys (a type of login key), Kubernetes secrets (keys used to run software systems), and AI provider keys. The firms said the exposure could affect more than 2,500 organizations and about 434,000 CI/CD pipelines, which are automated “assembly lines” companies use to build and ship software.
The reports named many large organizations as high-confidence victims, including Amazon Web Services, Samsung, Salesforce, Cisco, and Nvidia, among others. Independent researcher Kevin Beaumont said he confirmed the data appeared legitimate for multiple victim organizations.
If these secrets are still active, attackers could use them like copied keys to enter company systems, change software, or access data. The firms urged affected teams to replace and revoke exposed credentials, and to check specifically for LiteLLM versions 1.82.7 and 1.82.8.
Source: Arstechnica