A supply-chain attack on LiteLLM, an open-source AI development tool, has exposed credentials for over 434,000 CI/CD pipelines. The breach, which occurred during a 40-minute window in March, was discovered by security firms CloudSEK and Hudson Rock. The compromised data includes cloud keys, repository tokens, and AI provider keys that could grant access to more than 2,500 organizations. The attack exploited a previously infected version of the tool, which was downloaded from the Python Package Index repository.

The breach was traced to a 195TB file obtained by Hudson Rock, which revealed a massive amount of sensitive data. Security researchers confirmed the authenticity of the data, noting it contained credentials for major companies such as Microsoft, Amazon, and Salesforce. The compromised versions of LiteLLM included code that accessed infected machine memory, scraped its contents, and exfiltrated the data through an attacker-controlled channel. The data also included credentials for software pipelines maintained by tens of thousands of organizations.

The attack highlights the risks of poor AI security and rushed development practices. Kevin Beaumont, an independent security researcher, noted that the breach was not due to AI itself but rather due to inadequate DevOps security. "It’s a massive supply chain breach due to poor AI security—not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security," he said. Both firms are urging affected organizations to rotate credentials and audit their environments for compromised versions of LiteLLM.

Source: arstechnica