METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

LiteLLM Supply Chain Attack Exposes Credentials of 2,500 Organizations

In a single 40-minute window in March, access keys from Microsoft, Amazon, Samsung and others leaked out

LiteLLM Supply Chain Attack Exposes Credentials of 2,500 Organizations

Summary

  • Credentials from roughly 2,500 organizations were leaked in terabyte-scale volumes through a compromised version of the open-source AI development tool LiteLLM
  • CloudSEK and Hudson Rock estimated that credentials from about 434,000 CI/CD pipelines leaked during a 40-minute attack window that opened in March
  • The supply chain attack, which first infected the vulnerability scanner Trivy, spread to LiteLLM, KICS, and the Telnyx SDK, with the youth-heavy hacking group TeamPCP identified as being behind it

Somebody's AI coding assistant quietly exfiltrated data for 40 minutes. In that window, access keys from more than 2,500 organizations — including Microsoft, Amazon, Cisco, Samsung, and Salesforce — were siphoned off wholesale.

What happened in 40 minutes

Security firms CloudSEK and Hudson Rock disclosed the incident in succession last Tuesday and Wednesday (local time, August 11–12). According to the two companies, an attacker opened a mere 40-minute window in March through a compromised version of the open-source AI development tool LiteLLM, scraping memory from organizations that had downloaded that version from the Python package repository PyPI during that time. Hudson Rock said it confirmed the leak after analyzing 195 terabytes of files.

The leaked data included cloud access keys, repository tokens, SSH keys, Kubernetes secrets, package deployment credentials, environment variables, and even AI provider API keys. Materials published by Hudson Rock showed Salesforce's SALESFORCE_CLIENT_SECRET, Slack's SLACK_SIGNING_SECRET, and Microsoft Azure environment details exposed in plain form.

434,000 pipelines breached

The two firms estimated that credentials leaked from roughly 434,000 CI/CD (continuous integration/continuous deployment) pipelines. CI/CD is the pipeline that automatically builds, tests, and deploys code once a developer writes it — if these credentials are compromised, attackers can gain direct access ranging from source code to production servers.

However, the firms said pinpointing exactly which organizations were affected from the leaked data was not straightforward. For instance, numerous emails from the @siriusxm.com domain were found in the data, but the leak was traced not to satellite radio company SiriusXM itself but to the infrastructure of its subsidiary, AdsWizz.

Infected softwareRole
TrivyVulnerability scanner, initial point of infection
LiteLLMMulti-LLM API integration tool, conduit for this mass leak
KICSInfrastructure-as-code security scanning tool
Telnyx Python SDKSDK for telecommunications APIs
코드 편집기 화면에 여러 API 키와 시크릿 키가 포함된 환경 변수 설정 코드가 보임
이미지: Ars Technica

The chain started with Trivy

The breach of LiteLLM was not itself the initial point of entry. The widely used vulnerability scanner Trivy was infected first, and the supply chain attack spread from there to LiteLLM. The same campaign was found to have also infected the security tool KICS and Telnyx's Python SDK. All four infected packages contained code that accessed memory on infected devices, scraped its contents, and exfiltrated the data to attacker-designated channels.

TeamPCP has been named as the actor behind the attack — reportedly a loosely organized but highly capable hacking group made up mostly of teenagers. Independent security researcher Kevin Beaumont, who said he verified the authenticity of the data, remarked that the issue "isn't that AI is dangerous, but that companies have been rushing to adopt AI while leaving security lax."

AI development tools have become a new attack vector

LiteLLM is an open-source tool that unifies multiple large language model (LLM) APIs behind a single interface, letting developers call different models — from OpenAI, Anthropic, Google, and others — by changing just a single line of code. This layer, rapidly adopted by everyone from startups to major enterprises amid the generative AI boom, became the conduit for this attack.

Observers note that as companies rush to bolt on AI features, security vetting has fallen behind. On August 10, OpenAI announced GPT-5.6-Cyber, a model dedicated to cybersecurity, saying it was strengthening defensive capabilities — but this incident underscores the lesson that such defenses can be rendered moot if the trust chain of the supply chain itself collapses.

What changes now

No organization has yet publicly confirmed concrete damage from this leak, but most of the exposed credentials are likely still valid. Any organization that has not updated its LiteLLM version since March should prioritize rotating all related keys and reviewing access logs. The incident is not a flaw in the AI tool itself, but rather another demonstration of the risk inherent in the supply chain structure — where the infection of a single open-source package can simultaneously expose tens of thousands of organizations that use it. It's likely to stand as a case study of how far DevOps security practices have fallen behind the rush to adopt AI features.

Comments