LiteLLM Supply-Chain Attack Leaks Terabytes of Credentials, Hits Microsoft, Amazon, and More

Ars Technica AI · rss · 2026-08-13

Security firms CloudSEK and Hudson Rock revealed that compromised versions of LiteLLM, an open-source AI tool, were downloaded from PyPI in March, leading to credential theft within a 40-minute window. The stolen data includes cloud keys, repo tokens, SSH keys, and more, potentially affecting over 2,500 organizations. Hudson Rock discovered the breach after analyzing a 195TB file. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among those impacted.

Original post →

More from Safety

Safety channel →