Skip to content

Terabytes of credentials leaked in massive supply-chain attack

8.2 relevance
Score Breakdown
technical depth
8
novelty
7
actionability
9
community
8
strategic
9
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Massive supply-chain attack on AI package with credential leaks is critical for security and SDLC.

AI/ML arstechnica.com
A cartoon man runs across a white field of ones and zeroes.
Summary

A supply-chain attack on LiteLLM, an open-source AI tool, leaked terabytes of credentials from Microsoft, Amazon, Cisco, and over 2,500 other organizations. The compromise lasted only 40 minutes in March, during which compromised versions of LiteLLM from PyPI exfiltrated memory contents, exposing 434,000 CI/CD pipeline credentials. The attack originated from a previous compromise of the Trivy vulnerability scanner, attributed to the teenage-led TeamPCP group, highlighting poor DevOps security in AI toolchains.

Author

Dan Goodin — Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. A journalist with more than 25 years experience, he has been chronicling the...

More from Dan Goodin →