ELSEIF
Your brief EB
428 stories from 97 feeds 266 clusters Refreshed 12 minutes ago next pull 00:22

TECH Signal 454

Terabytes of credentials leaked in massive supply-chain attack

A supply-chain attack that poisoned LiteLLM and three other packages scraped machine memory and exfiltrated credentials from thousands of organizations, including Microsoft, Amazon, and Samsung.

WHY IT MATTERS

Any team that ran the compromised LiteLLM versions during the active window may have leaked cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider keys from their CI/CD pipelines. The attack chain began with a prior compromise of the vulnerability scanner Trivy, meaning standard dependency hygiene would not have caught it. Organizations on the high-confidence exposure list should treat all pipeline credentials as compromised and rotate them.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Security firms CloudSEK and Hudson Rock found credentials from more than 2,500 organizations in a 195TB file analyzed after the attack.

02

The compromised packages, LiteLLM, Trivy, KICS, and the Telnyx Python SDK, contained code that scraped machine memory and exfiltrated contents through an attacker-controlled channel.

03

TeamPCP, a group largely made up of teenagers, took credit for the attack and researchers have largely corroborated the claim.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Ars Technica Terabytes of credentials leaked in massive supply-chain attack Open ↗