A massive supply-chain attack on LiteLLM has resulted in the exposure of terabytes of sensitive credentials belonging to major organizations like Microsoft, Amazon, and Cisco. This breach was revealed by security firms CloudSEK and Hudson Rock and affected over 2,500 organizations during a 40-minute window when the victims used compromised versions of LiteLLM from the Python Package Index.
The attackers, identified as the group TeamPCP, accessed memory on infected machines to exfiltrate data, including cloud keys and CI/CD pipeline credentials, impacting approximately 434,000 software pipelines. Security experts urge organizations to rotate affected credentials and audit their systems to mitigate risks. This incident highlights the growing threat of supply-chain attacks and the need for improved security measures in the software development environment.