August 31, 2026ADMIN

LiteLLM supply-chain attack exposed credentials from thousands of organizations

Compromised LiteLLM packages extracted cloud keys, repository tokens and other credentials tied to more than 2,500 organizations during a 40-minute window.

LiteLLM supply-chain attack exposed credentials from thousands of organizations

A supply-chain compromise involving LiteLLM exposed terabytes of credentials connected to some of the world’s largest and most sensitive organizations. LiteLLM is an open source tool designed to streamline AI-driven software development.

The incident involved compromised versions of LiteLLM distributed through the package’s official location in the Python Package Index repository. According to security firms CloudSEK and Hudson Rock, credentials were extracted during a 40-minute period in March. The exposed secrets were tied to more than 2,500 organizations.

What happened during the LiteLLM compromise

Victims downloaded and used compromised versions of LiteLLM from the package’s official Python Package Index location. During a 40-minute window, those versions extracted credentials from affected environments.

The available reporting does not identify the specific compromised versions or explain how the malicious releases reached the official package location. It also does not say who was responsible for the attack.

CloudSEK disclosed its findings on Tuesday, followed by a separate disclosure from Hudson Rock on Wednesday. Both firms described a breach with potential consequences across a large number of organizations using the open source AI development tool.

The short extraction period is a central detail of the incident. Despite lasting only 40 minutes, the compromise exposed a broad collection of access secrets from thousands of organizations.

More than 2,500 organizations potentially affected

CloudSEK said the exposed credentials could allow attackers to gain access to more than 2,500 organizations. Microsoft, Amazon, Cisco, Samsung and Salesforce were among the entities whose secrets were exposed, although they represented only a small selection of those affected.

The reporting does not provide a complete list of organizations. It also does not specify how many credentials belonged to each entity, whether every exposed credential remained active or whether attackers subsequently used any of the secrets.

Hudson Rock said it discovered the incident after analyzing a 195TB file it had obtained. The firm did not identify where that file came from. CloudSEK also did not disclose the source of its information.

While the overall exposure involved terabytes of credentials, the available information does not establish that the entire 195TB file consisted of access secrets from the LiteLLM incident.

Types of credentials exposed

CloudSEK identified several categories of sensitive information in the exposed data:

  • Cloud keys
  • Repository tokens
  • SSH keys
  • Kubernetes secrets
  • Package publishing credentials
  • Environment variables
  • AI provider keys

The range of exposed material indicates that the compromise reached beyond a single type of account or service. The affected information included credentials associated with cloud platforms, software repositories, Kubernetes environments, package publishing and AI providers.

CloudSEK warned that these secrets could enable access to affected organizations. However, the disclosures summarized here do not detail which systems were accessible through individual credentials or how much access each secret provided.

Why this is a supply-chain incident

The breach is categorized as a supply-chain attack because it centered on compromised versions of a software package used by other organizations. Rather than describing separate attacks against more than 2,500 entities, the findings point to LiteLLM as the shared component through which credentials were extracted.

The fact that victims obtained the compromised versions from the package’s official Python Package Index location is significant. The reported distribution path was not an unofficial download site or an unrelated copy of the software; it was LiteLLM’s official package location in the repository.

LiteLLM’s role in AI-driven software development also gave the incident a wide organizational reach. The exposed credentials included both conventional development secrets and keys associated with AI providers.

What remains unknown

The disclosures establish the scale and timing of the credential exposure, but several important details remain unavailable. The reports summarized here do not identify:

  • The party responsible for compromising LiteLLM
  • The source of the information obtained by either security firm
  • The exact LiteLLM versions affected
  • How the compromised packages entered the official repository location
  • How many exposed credentials were active
  • Whether the credentials were used after being extracted
  • The complete list of affected organizations

These gaps make it difficult to determine the full operational impact from the disclosures alone. The confirmed facts are that compromised LiteLLM packages extracted multiple types of credentials during a 40-minute window in March, and that the exposed secrets were associated with more than 2,500 organizations.

Conclusion

The LiteLLM incident combined a trusted package location, a widely used development tool and a broad collection of sensitive credentials. Although the extraction window lasted only 40 minutes, the resulting exposure involved terabytes of secrets and potentially affected thousands of organizations. Key questions about the attacker, the compromised versions and any subsequent use of the credentials remain unanswered.

Original reporting: Ars.


Originally reported by Ars.