THE LiteLLM Supply-Chain Attack, attributed to the threat actor group TeamPCP, has compromised credentials across 2,038 repositories, with substantial impacts on various sectors, especially technology, finance, and healthcare. The attack exploited a backdoor in the LiteLLM open-source AI application, affecting over 2,500 organizations and exposing critical credentials like cloud keys and API tokens.
Security experts caution that many victim organizations remain unaware of the breach, emphasizing the need for credential rotation and revocation. Key affected companies include Microsoft, IBM, and Deloitte, among others, highlighting the widespread risk across industries.