Terabytes of credentials leaked in massive supply-chain attack
Ars Technica

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock.

CloudSEK said it found:

  • cloud keys
  • repository tokens
  • SSH keys
  • Kubernetes secrets
  • package publishing credentials
  • environment variables
  • AI provider keys

According to CloudSEK, these credentials could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

A prior supply-chain attack

The LiteLLM compromise was the result of a previous supply-chain attack that infected the widely used vulnerability scanner Trivy. Other software infected in the campaign includes KICS and the Telnyx Python SDK.

Attribution

TeamPCP, a ramshackle but extremely capable gang largely made up of teenagers, took credit for the attack, and researchers have largely corroborated the claim.

β€œI’ve confirmed the data is legit by the way, multiple victim orgs,” independent security researcher Kevin Beaumont said. β€œIt contains a significant volume of sensitive content at orgs. It’s a massive supply chain breach due to poor AI security-not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security.”

Read on Ars Technica ↗ ← Back to News

Comments

No comments yet. Start the discussion.