Tech

Massive supply-chain attack exposes terabytes of credentials from Microsoft, Amazon and others

Security firms CloudSEK and Hudson Rock reveal the scale of the TeamPCP breach, urging immediate credential rotation and environment audits across the global software development sector.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · View original source
Terabytes of credentials leaked in massive supply-chain attack
Compromised versions of LiteLLM and other open-source tools led to the exfiltration of secrets from 2,500 organisations and 434,000 CI/CD pipelines

Terabytes of sensitive credentials belonging to major global organisations, including Microsoft, Amazon, Cisco, Samsung and Salesforce, have been exposed following a sophisticated supply-chain attack on LiteLLM, an open-source artificial intelligence software development tool. The breach, attributed to the group TeamPCP, compromised versions of the software downloaded from the Python Package Index repository in March, scraping and exfiltrating data from approximately 2,500 organisations during a 40-minute window.

Security firms CloudSEK and Hudson Rock detailed the findings in reports released on Tuesday and Wednesday. CloudSEK identified a vast array of exposed data, including cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables and AI provider keys. The firms determined that the compromised versions of LiteLLM, along with other infected software such as Trivy, KICS and the Telnyx Python SDK, contained malicious code designed to access machine memory and exfiltrate contents through an attacker-controlled channel.

The attack affected an estimated 434,000 continuous integration and continuous delivery (CI/CD) pipelines. Hudson Rock, which made its discovery after analysing a 195TB file, noted that many CI/CD pipelines are configured generically. Consequently, the dumped variables often contained active database passwords, third-party API keys and cloud credentials without identifiable company emails or internal server names, leaving countless organisations unaware of their exposure.

Independent security researcher Kevin Beaumont confirmed the legitimacy of the data, noting that multiple victim organisations had verified the breach. He attributed the scale of the incident to poor DevOps security and the industry’s rush to integrate AI, stating that the attackers, largely composed of teenagers, were able to outmanoeuvre organisations focused on rapid deployment rather than robust security protocols.

In response to the breach, both firms have issued urgent recommendations for affected entities. Hudson Rock instructed organisations using AI proxy infrastructure or third-party CI/CD vulnerability scanners to immediately audit their environments for LiteLLM versions 1.82.7 and 1.82.8. The firm advised aggressive credential revocation, including the invalidation and rotation of all cloud keys, Kubernetes service account tokens and GitLab or GitHub personal access tokens.

CloudSEK highlighted a specific failure in the Trivy supply chain, where developers rotated but failed to fully revoke an automation token over a 20-day window. This lapse provided attackers with nearly three weeks to force-push malicious code to third-party builds. Alon Gal, co-founder and chief technology officer of Hudson Rock, emphasised that the magnitude of the breach, where a 40-minute window led to the harvesting of millions of secrets, necessitates a new level of vigilance and response from the cybersecurity industry.

Continue reading

More from Tech

Read next: Microsoft sets out human-control principles in 37-page AI code
Read next: GitHub project brings Meta Neural Band gestures to macOS
Read next: What Background App Refresh does on iPhone