A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains — including AWS, Samsung, Cisco and Salesforce — according to Hudson Rock research published August 13. The archive contains 433,909 files, with 118,829 CI runner dumps attributed to 2,488 corporate domains.
A Poisoned Scanner
LiteLLM is an open-source proxy gateway developers use to route requests to different AI models. The breach had its roots in an earlier compromise of Trivy, a popular open-source vulnerability scanner: on March 19, cybercriminal group TeamPCP used stolen credentials to publish a compromised Trivy version. LiteLLM's build pipeline installed Trivy automatically, giving the poisoned scanner read access to the runner environment and letting attackers steal the project's PyPI publishing tokens, which they used to publish two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, on March 24.
One Window, Thousands of Victims
The dataset contains information linked to organizations including NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte and Siemens, with screenshots showing AWS secret access keys, Salesforce client secrets, Slack signing secrets and AI provider API keys. A roughly 40-minute window in which the dependency was hacked led to over 430,000 instances where secrets were harvested, Hudson Rock's Gal said. CloudSEK, working from a separate dataset of about 434,000 stolen files, put the number of exposed organizations at close to 2,500, and security researcher Kevin Beaumont confirmed the data is legit. Hudson Rock urges organizations to audit for LiteLLM versions 1.82.7 and 1.82.8, rotate cloud IAM keys and treat any secrets accessible to the LiteLLM environment as compromised.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.