💻
LiteLLM supply-chain attack exposes credentials of 2,500+ organisations
💻 Technology

LiteLLM supply-chain attack exposes credentials of 2,500+ organisations

Attackers compromised LiteLLM, an open-source AI development tool, injecting malicious code into its official Python Package Index release. During a 40-minute window in March, credentials belonging to over 2,500 organisations were stolen, including cloud keys, SSH keys, Kubernetes secrets and AI provider tokens. Among the affected entities are Microsoft, Amazon, Cisco, Samsung and Salesforce, according to security firms CloudSEK and Hudson Rock.

Comments

No comments yet