
Summary
- Credentials from roughly 2,500 organizations were leaked in terabyte-scale volumes through a compromised version of the open-source AI development tool LiteLLM
- CloudSEK and Hudson Rock estimated that credentials from about 434,000 CI/CD pipelines leaked during a 40-minute attack window that opened in March
- The supply chain attack, which first infected the vulnerability scanner Trivy, spread to LiteLLM, KICS, and the Telnyx SDK, with the youth-heavy hacking group TeamPCP identified as being behind it
Somebody's AI coding assistant quietly exfiltrated data for 40 minutes. In that window, access keys from more than 2,500 organizations — including Microsoft, Amazon, Cisco, Samsung, and Salesforce — were siphoned off wholesale.
What happened in 40 minutes
Security firms CloudSEK and Hudson Rock disclosed the incident in succession last Tuesday and Wednesday (local time, August 11–12). According to the two companies, an attacker opened a mere 40-minute window in March through a compromised version of the open-source AI development tool LiteLLM, scraping memory from organizations that had downloaded that version from the Python package repository PyPI during that time. Hudson Rock said it confirmed the leak after analyzing 195 terabytes of files.
The leaked data included cloud access keys, repository tokens, SSH keys, Kubernetes secrets, package deployment credentials, environment variables, and even AI provider API keys. Materials published by Hudson Rock showed Salesforce's SALESFORCE_CLIENT_SECRET, Slack's SLACK_SIGNING_SECRET, and Microsoft Azure environment details exposed in plain form.
434,000 pipelines breached
The two firms estimated that credentials leaked from roughly 434,000 CI/CD (continuous integration/continuous deployment) pipelines. CI/CD is the pipeline that automatically builds, tests, and deploys code once a developer writes it — if these credentials are compromised, attackers can gain direct access ranging from source code to production servers.
However, the firms said pinpointing exactly which organizations were affected from the leaked data was not straightforward. For instance, numerous emails from the @siriusxm.com domain were found in the data, but the leak was traced not to satellite radio company SiriusXM itself but to the infrastructure of its subsidiary, AdsWizz.
| Infected software | Role |
|---|---|
| Trivy | Vulnerability scanner, initial point of infection |
| LiteLLM | Multi-LLM API integration tool, conduit for this mass leak |
| KICS | Infrastructure-as-code security scanning tool |
| Telnyx Python SDK | SDK for telecommunications APIs |

The chain started with Trivy
The breach of LiteLLM was not itself the initial point of entry. The widely used vulnerability scanner Trivy was infected first, and the supply chain attack spread from there to LiteLLM. The same campaign was found to have also infected the security tool KICS and Telnyx's Python SDK. All four infected packages contained code that accessed memory on infected devices, scraped its contents, and exfiltrated the data to attacker-designated channels.
TeamPCP has been named as the actor behind the attack — reportedly a loosely organized but highly capable hacking group made up mostly of teenagers. Independent security researcher Kevin Beaumont, who said he verified the authenticity of the data, remarked that the issue "isn't that AI is dangerous, but that companies have been rushing to adopt AI while leaving security lax."
AI development tools have become a new attack vector
LiteLLM is an open-source tool that unifies multiple large language model (LLM) APIs behind a single interface, letting developers call different models — from OpenAI, Anthropic, Google, and others — by changing just a single line of code. This layer, rapidly adopted by everyone from startups to major enterprises amid the generative AI boom, became the conduit for this attack.
Observers note that as companies rush to bolt on AI features, security vetting has fallen behind. On August 10, OpenAI announced GPT-5.6-Cyber, a model dedicated to cybersecurity, saying it was strengthening defensive capabilities — but this incident underscores the lesson that such defenses can be rendered moot if the trust chain of the supply chain itself collapses.
What changes now
No organization has yet publicly confirmed concrete damage from this leak, but most of the exposed credentials are likely still valid. Any organization that has not updated its LiteLLM version since March should prioritize rotating all related keys and reviewing access logs. The incident is not a flaw in the AI tool itself, but rather another demonstration of the risk inherent in the supply chain structure — where the infection of a single open-source package can simultaneously expose tens of thousands of organizations that use it. It's likely to stand as a case study of how far DevOps security practices have fallen behind the rush to adopt AI features.





Comments