Massive Supply-Chain Attack Exposes Thousands of Organization Credentials
A critical security breach has exposed terabytes of sensitive credentials from over 430,000 CI/CD pipelines across major organizations like Microsoft, Amazon, Cisco, and Salesforce. The attack exploited a compromised version of the open-source LiteLLM tool, which was infected through a supply-chain attack on Trivy, a vulnerability scanner. During a 40-minute window in March, attackers scraped data from 2,500 users, exfiltrating cloud keys, SSH credentials, and AI provider tokens. Security firms CloudSEK and Hudson Rock discovered the breach after analyzing a 195TB file, revealing that many organizations had generic configurations making their secrets easily accessible. The compromised LiteLLM versions included malicious code to steal data from infected machines. Researchers confirmed the breach’s scale, emphasizing poor DevOps security practices enabled the attack. Affected companies are urged to rotate credentials and audit systems, as some organizations failed to secure their secrets despite the exposure. This incident highlights the evolving threat of supply-chain attacks, where a single compromised dependency can impact thousands of entities simultaneously.
