
A supply-chain attack on LiteLLM, a widely used open source AI development tool, exposed terabytes of sensitive credentials belonging to over 2,500 organizations—including Microsoft, Amazon, Cisco, Samsung, and Salesforce—during a 40-minute window in March.
The compromised versions scraped credentials from machines' memory and exfiltrated them, leaving 434,000 CI/CD pipelines with exposed database passwords, cloud keys, and API tokens.
Security researchers warn that many affected organizations have not rotated these credentials and remain unaware of the breach, creating a window for attackers to gain unauthorized access.
What happened
Attackers compromised LiteLLM, an open source AI development tool, and extracted terabytes of credentials—including cloud keys, SSH keys, and API tokens—from 2,500 organizations during a 40-minute window in March. The credentials belonged to major firms including Microsoft, Amazon, Cisco, Samsung, Salesforce, Nvidia, and dozens of others. TeamPCP, a group largely made up of teenagers, claimed responsibility.
Why it matters
The attack exposed 434,000 CI/CD (continuous integration/continuous delivery) software pipelines—automated systems that deploy code—leaving organizations with active database passwords, cloud credentials, and third-party API keys sitting exposed and often unaware of the breach. Security researchers found that many organizations have not rotated these credentials even months later, leaving them vulnerable to attackers who can use the exposed secrets to access internal systems and data.
What to watch
Organizations that used LiteLLM versions 1.82.7 and 1.82.8 should immediately audit their environments and perform aggressive credential rotation across all cloud keys, Kubernetes tokens, and GitHub/GitLab access. The breach underscores a broader pattern: when a single upstream open source tool is compromised, the infection spreads simultaneously across thousands of companies that depend on it.
On Tuesday and Wednesday, security firms CloudSEK and Hudson Rock revealed that attackers had compromised LiteLLM, an open source tool widely used to streamline AI-driven software development. The attack exposed terabytes of credentials belonging to more than 2,500 organizations, with high-confidence evidence that major firms including Nvidia Corporation, Amazon Web Services, Samsung Electronics, Salesforce, Cisco Systems, F. Hoffmann-La Roche, ServiceNow, Siemens AG, S&P Global, Airbus US Space & Defense, John Deere, Regeneron Pharmaceuticals, London Stock Exchange Group, Thomson Reuters, FedEx, and many others had their secrets compromised.
The breach occurred during a 40-minute window in March when organizations downloaded and ran two compromised versions of LiteLLM (versions 1.82.7 and 1.82.8) from the official Python Package Index repository. The malicious code accessed the memory of infected machines, scraped its contents, and exfiltrated the data through an attacker-controlled channel. Hudson Rock obtained a 195TB file containing the stolen data, though neither firm identified the source of the attack. The compromise was part of a larger campaign: the group also infected Trivy, a vulnerability scanner, as well as KICS and the Telnyx Python SDK. TeamPCP, a group largely made up of teenagers, claimed credit for the attack, and researchers have corroborated the claim.
The scale of the fallout was enormous. In total, some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed. The data contained cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys. Many of the exposed secrets belonged to sensitive platforms: Salesforce client secrets, Slack signing secrets, Microsoft Azure environment credentials, and countless database passwords and third-party API tokens without identifying company names or internal server details.
Security researchers emphasized the depth of the problem. Hudson Rock noted that "many CI/CD pipelines are configured generically" and that "the dumped variables contain active database passwords, third-party API keys, and cloud credentials without any identifiable company email, custom domain string, or internal server name. This means countless organizations currently have active secrets sitting in this database, completely unaware of their exposure." Independent security researcher Kevin Beaumont confirmed the legitimacy of the data and warned that the scale reflected both poor AI security practices and weak DevOps hygiene at major organizations. He later reported that at least one of the biggest U.S. technology companies had failed to rotate exposed credentials months after the disclosure, despite claiming they had done so.
Both firms urged immediate action. Hudson Rock instructed any organization that used compromised versions of LiteLLM to audit their environment and perform "aggressive credential revocation," assume all secrets accessible to the LiteLLM environment were compromised, and invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitHub/GitLab personal access tokens. Hudson Rock also flagged a cautionary lesson from the Trivy breach: developers had rotated but failed to fully revoke an automation token over a 20-day window, giving attackers a three-week period to force-push malicious code to downstream users. Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote: "A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry."
The LiteLLM compromise was not an isolated incident but part of a broader campaign by TeamPCP targeting critical infrastructure in the open source software supply chain. The group previously compromised Trivy, a widely used vulnerability scanner, and also infected KICS and the Telnyx Python SDK. The attack exploited a weakness common across many organizations: the integration of third-party open source tools into deployment pipelines without sufficient isolation or monitoring. When a single upstream dependency is infected, the malware spreads to every downstream user within minutes—in this case, 2,500 organizations in 40 minutes.
A key vulnerability in the incident was credential management at both the tool provider and the victim organizations. CloudSEK and Hudson Rock noted that CI/CD pipelines are often configured to store credentials as environment variables without additional safeguards, and that many organizations failed to rotate these secrets even after the breach was disclosed. Independent security researcher Kevin Beaumont confirmed that credentials exposed in March remained active months later at some of the largest U.S. technology companies, suggesting that organizational response has been inadequate. The researchers also flagged a secondary lesson: Trivy developers rotated a compromised automation token but failed to fully revoke it, creating a 20-day window during which attackers could continue to inject malicious code into downstream projects.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
DeepSeek released V4 Pro 0813, its latest Pro model, available through OpenRouter via API

Designers Isaque Seneda and Gabriel Abrucio created ShieldFont, a font that uses ligatures to replace common w…

Twitch announced today that users can now opt out of allowing Amazon to use their streams, VODs, clips, chats…

The Trump administration has developed an AI framework requiring federal safety testing of the most powerful U…

Anthropic added invisible watermarks to Claude's outputs to comply with the EU AI Act's requirement that AI-ge…

STATION AI and Denso have launched RE-CORE, an open innovation support program aimed at manufacturers

The AI news that matters, in one minute each morning.
Sign up free