LiteLLM Supply-Chain Attack Leaks Terabytes of Credentials from Microsoft and Amazon

GinJockette · reddit · 2026-08-13

Security firms CloudSEK and Hudson Rock revealed that LiteLLM, an open-source AI development tool, recently suffered a severe supply-chain attack. Attackers planted compromised versions of LiteLLM in the Python Package Index (PyPI) repository in March.

During a 40-minute window while victims used the malicious package, attackers extracted a massive 195TB of credentials. The leaked data included cloud keys, repository tokens, SSH keys, and AI provider API keys, compromising over 2,500 organizations including giants like Microsoft, Amazon, Cisco, and Samsung.

Related event: LiteLLM Supply Chain Attack Exposes Thousands of Keys(2 posts)→

Original post →

More from coding & agent

coding & agent channel →