LiteLLM Supply-Chain Attack Leaks Terabytes of Credentials, Hits Microsoft, Amazon, and More
Ars Technica AI · rss · 2026-08-13
Security firms CloudSEK and Hudson Rock revealed that compromised versions of LiteLLM, an open-source AI tool, were downloaded from PyPI in March, leading to credential theft within a 40-minute window. The stolen data includes cloud keys, repo tokens, SSH keys, and more, potentially affecting over 2,500 organizations. Hudson Rock discovered the breach after analyzing a 195TB file. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among those impacted.
More from Safety
- AI Policy Researcher Calls for Public Guidance on Defining 'Frontier' Models — evijit · 2026-08-13
- Africa AI Policy Opportunities Digest Released: Funding, Events, and Courses — ChinasaTOkolo · 2026-08-13
- Rising AI Security Incidents Make Dedicated Defense Agents Inevitable — ziv_ravid · 2026-08-13
- White House Plans to Bring Open AI Models Under Secret Prerelease Safety Testing — kimmonismus · 2026-08-13
- Malicious VS Code Extensions Disguised as Dev Tools Hide Backdoors and Shellcode — cyb3rops · 2026-08-13
- Anthropic's New Claude Watermarking Sparks User Backlash Over Cheating Detection — TechCrunch AI · 2026-08-13