Terabytes of credentials leaked in massive supply-chain attack



The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

“The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

Post updated to add image.



Source link

  • Related Posts

    Today’s NYT Strands Hints, Answers and Help for Oct. 7, #948

    Looking for the most recent NYT Strands puzzle answers? CNET publishes daily answers and hints for The New York Times Mini Crossword, Connections, Connections: Sports Edition and Strands puzzles. Strands…

    Continue reading
    Sebastian Maniscalco’s SiriusXM channel is hurting up-and-coming talent, comics say

    Comedian Sebastian Maniscalco is facing backlash from fellow comics who claim his takeover of SiriusXM’s Raw Comedy channel is harming up-and-coming talent, as reported earlier by Deadline. Many established comics,…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    11 Elegant Amazon Prime Finds My French Friend Recommends

    11 Elegant Amazon Prime Finds My French Friend Recommends

    Shell third quarter 2026 update note

    Test cricket’s biggest scandals: Your top 10 revealed

    Test cricket’s biggest scandals: Your top 10 revealed

    Today’s NYT Strands Hints, Answers and Help for Oct. 7, #948

    Today’s NYT Strands Hints, Answers and Help for Oct. 7, #948

    Delta Airbus A350 Winglet Wedged In Air Canada Boeing 777’s Tail After LAX Collision

    Delta Airbus A350 Winglet Wedged In Air Canada Boeing 777’s Tail After LAX Collision

    Yellow labs make first leaf pile jump of this fall season

    Yellow labs make first leaf pile jump of this fall season