Major 153GB of Stolen Credentials Exposed in LiteLLM Supply Chain Attack

www.news4hackers.com-major-153gb-of-stolen-credentials-exposed-in-litellm-supply-chain-attack-major-153gb-of-stolen-credentials-exposed-in-litellm-supply-chain-attack

A 153GB dataset containing compromised credentials and sensitive information has emerged following a supply chain attack targeting the LiteLLM project.

The Breach Overview

A 153GB dataset containing compromised credentials and sensitive information has emerged following a supply chain attack targeting the LiteLLM project. The breach, traced to a compromised build pipeline, exposed data linked to thousands of corporate domains, including major organizations such as AWS, Samsung, Cisco, and Salesforce.

The Attack Vector

Hudson Rock, a security research group, confirmed the dataset contains 433,909 files, with 118,829 CI runner dumps associated with 2,488 corporate domains. The group stated they are conducting an ethical disclosure initiative to enable affected entities to mitigate risks before malicious actors exploit the data.

Alon Gal, co-founder and CTO of Hudson Rock, emphasized the urgency of the situation, stating that the attack underscores the need for proactive security measures in AI infrastructure.

Impact and Scope

LiteLLM, an open-source proxy gateway used for routing AI model requests, became a vector for the attack after an earlier compromise of Trivy, a widely adopted open-source vulnerability scanner. On March 19, 2026, the cybercriminal group TeamPCP, which emerged in late 2025, leveraged stolen credentials to distribute a malicious version of Trivy.

CloudSEK, another security firm, analyzed a separate dataset of 434,000 files and estimated the number of affected organizations at nearly 2,500. The company noted that these figures represent exposure rather than confirmed breaches.

Security researcher Kevin Beaumont verified the authenticity of the data, stating it contains a significant volume of sensitive information across organizations. He criticized the industry’s rush to deploy AI solutions without adequate DevOps security practices.

Response and Recommendations

Hudson Rock’s Call to Action

Hudson Rock urged entities using AI proxy infrastructure, third-party CI/CD scanners, or downstream AI packages to audit their environments for LiteLLM versions 1.82.7 and 1.82.8. Affected organizations should rotate cloud IAM keys, review audit logs for suspicious activity dating back to March 24, and inspect for unauthorized.pth files or anomalous systemd services.

Hudson Rock highlighted the challenges of identifying affected entities, as many files lack clear ownership markers. For example, a leaked pipeline linked to a SiriusXM committer was traced to AdsWizz, a subsidiary, through infrastructure indicators such as a self-hosted GitLab instance.

Industry Implications

The breach has prompted calls for enhanced security practices in AI and DevOps workflows. Gal noted that the scale of the incident necessitates a paradigm shift in how the cybersecurity industry responds to supply chain threats. The incident also highlights the growing risks associated with open-source dependencies and the importance of securing build pipelines against adversarial compromises.

One example cited by Beaumont involved a major U.S. tech company that claimed to have rotated credentials but found that most remained valid. The incident underscores the critical need for immediate remediation.

Conclusion

The breach highlights the cascading impact of supply chain vulnerabilities, as a 40-minute window of compromised dependency management led to the collection of over 430,000 instances of sensitive secrets. Despite the dataset’s current lack of public circulation, the group warned that delayed action could lead to widespread exploitation.



About Author

en_USEnglish