LiteLLM Supply-Chain Attack Leaks Terabytes of Credentials from Microsoft and Amazon
GinJockette · reddit · 2026-08-13
Security firms CloudSEK and Hudson Rock revealed that LiteLLM, an open-source AI development tool, recently suffered a severe supply-chain attack. Attackers planted compromised versions of LiteLLM in the Python Package Index (PyPI) repository in March.
During a 40-minute window while victims used the malicious package, attackers extracted a massive 195TB of credentials. The leaked data included cloud keys, repository tokens, SSH keys, and AI provider API keys, compromising over 2,500 organizations including giants like Microsoft, Amazon, Cisco, and Samsung.
Related event: LiteLLM Supply Chain Attack Exposes Thousands of Keys(2 posts)→
More from coding & agent
- How Do Agentic Payments Work? Coinbase Expert Explains x402 — MurrLincoln · 2026-08-13
- Using Claude Code to Read Source Code Beats Manual GUI Checking — yuwen_lu_ · 2026-08-13
- Open-source ios-builder lets you build iOS apps from Windows/Linux via GitHub Actions — tom_doerr · 2026-08-13
- Malicious VS Code Extensions Disguised as Dev Tools Hide Backdoors and Shellcode — cyb3rops · 2026-08-13
- Research Traces Failures in Automated ML Training Agents and Proposes Model-Agnostic Fixes — micahgoldblum · 2026-08-13
- Grok Bot Deeply Integrates with Cursor Cloud Agents as a Task Manager — altryne · 2026-08-13