Terabytes of credentials leaked in massive supply-chain attack

| Source: Ars Technica AI

Tags: LiteLLM, supply-chain attack, cybersecurity, credentials, Trivy, AI security, TeamPCP

A supply-chain attack on LiteLLM exposed credentials from Microsoft, Amazon, Cisco, Samsung, and 2,500+ organizations during a 40-minute window in March, with 195TB of data including cloud keys, SSH keys, Kubernetes secrets, and AI provider API keys now in attacker hands.

Details

A supply-chain attack starting with a compromised vulnerability scanner (Trivy) cascaded through LiteLLM, KICS, and the Telnyx Python SDK, exfiltrating terabytes of credentials from organizations that ran the infected packages. The attack window was just 40 minutes in March, but the damage is extensive: security firms CloudSEK and Hudson Rock found cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider API keys from more than 2,500 organizations. The 195TB dataset analyzed by Hudson Rock contained credentials from 434,000 CI/CD pipelines. High-profile victims include Microsoft, Amazon, Cisco, Samsung, and Salesforce. Teenager-led group TeamPCP claimed responsibility; independent researcher Kevin Beaumont confirmed the data's legitimacy: 'It contains a significant volume of sensitive content at orgs. It's a massive supply chain breach due to poor AI security — not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI.' What makes this especially alarming for AI teams: LiteLLM specifically manages AI API calls across multiple providers, meaning exposed keys likely include OpenAI, Anthropic, and cloud AI credentials alongside standard infrastructure secrets. Organizations rushing to integrate AI tools without supply chain security practices created the attack surface.