LIVE · cybersecurity feed
Live wire
ai

153GB of stolen credentials surface after LiteLLM supply chain attack

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global et

zeroday.news ·

A substantial archive of 153GB containing credentials and other sensitive information, reportedly stolen during a supply chain attack involving the open-source proxy gateway LiteLLM, has surfaced. The data is linked to thousands of corporate domains, including major entities like AWS, Samsung, Cisco, and Salesforce.

Hudson Rock, a cybersecurity firm, claims to have obtained and analyzed the archive, which comprises 433,909 files. Their analysis attributes 118,829 CI runner dumps to 2,488 distinct corporate domains. The firm has initiated a global ethical disclosure effort to assist organizations in proactively responding to the exposure before the data is potentially weaponized by threat actors.

LiteLLM, an open-source proxy gateway utilized by developers to route requests to various AI models, was compromised following an earlier breach of Trivy, a widely used open-source vulnerability scanner. On March 19, 2026, the cybercriminal group TeamPCP, which emerged in late 2025, allegedly used stolen credentials to publish a malicious version of Trivy.

LiteLLM's build pipeline automatically installed Trivy, granting the poisoned scanner read access to the runner environment. This access allowed the attackers to steal LiteLLM's PyPI publishing tokens. Leveraging these tokens, TeamPCP subsequently published two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, to the Python Package Index on March 24.

The exposed dataset includes information tied to organizations such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte, and Siemens. Screenshots accompanying the research reportedly show AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys captured during pipeline execution.

Another cybersecurity firm, CloudSEK, working with a separate dataset of approximately 434,000 stolen files, estimates the number of exposed organizations to be close to 2,500. CloudSEK emphasizes that these figures represent potential exposure rather than confirmed breaches.

Identifying the specific owners of the exposed secrets presents a challenge. Hudson Rock notes that accurate attribution requires analyzing infrastructure boundaries beyond surface-level indicators. For instance, a leaked pipeline might be linked to a committer email at one company, but infrastructure markers in the same data dump could point to a subsidiary. A significant portion of the dumped files lack clear ownership, containing database passwords, third-party API keys, and cloud credentials without identifying company email addresses, custom domains, or internal server names. This means some organizations may have exposed credentials without being aware of their compromise.

Hudson Rock is urging organizations that use AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for LiteLLM versions 1.82.7 and 1.82.8. Any secrets accessible to the LiteLLM environment should be considered compromised. Recommended actions include rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity dating back to March 24, and checking for unauthorized .pth files and suspicious systemd services.

Despite the scale of the exposure, some organizations reportedly appear to be addressing the findings with less urgency than warranted. One major US tech company, for example, claimed to have rotated all affected credentials, yet subsequent testing by a security researcher found many of them still active.

Hudson Rock states that the data is not currently circulating widely, presenting a critical window of opportunity for companies to rotate keys and secrets before a wider leak occurs. The firm emphasizes that the magnitude of this incident necessitates a new level of response from the cybersecurity industry.

aicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.