posted in Technology

Terabytes of credentials leaked in massive supply-chain attack

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
A cartoon man runs across a white field of ones and zeroes.Ars TechnicaTerabytes of credentials leaked in massive supply-chain attackThe data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Replying to an earlier post

Can anyone who works in the security space tell me if we are as cooked as I think we are?

With ai I’m assuming any script kiddie with motivation has access to a SIGNIFICANTLY larger surface area of attacks. And sometimes I do stupid things like wait an extra few days before updating my pc/software.

I have this suspicion that everything digital is far more vulnerable now than it ever was. But I have only surface level knowledge in the space. Is it as bleak as I think?

Replying to an earlier post

Not really, lot of this is hyped up sales bullshit. The reality is that security software has been getting better and better. It’s not this ecosystem of “that matches this hash or IP” anymore. For the last decade ML has been used heavily. It doesn’t look for just the stuff it knows is bad, it looks for things that are out of place.

End of the day…you can’t fix everything and you can’t fix your users…but the script kiddies aren’t what to worry about, it’s the large gov backed groups. Those have always been the problem.

en