HeadlinesBriefing favicon HeadlinesBriefing.com

Massive Lite LLM supply-chain attack leaks terabytes of credentials

Ars Technica •
×

Terabytes worth of credentials, many from the world’s biggest organizations, have been exposed in a supply-chain attack on Lite LLM, an open-source AI development tool. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the victims. Security firms Cloud SEK and Hudson Rock disclosed the breach on Tuesday and Wednesday, revealing cloud keys, repository tokens, SSH keys, and more that could allow access to over 2,500 organizations.\n\nThe credentials were extracted during a 40-minute window in March while victims used compromised Lite LLM versions from the Python Package Index. The attack originated from a prior supply-chain compromise of the Trivy vulnerability scanner, also affecting KICS and the Telnyx Python SDK.

Group Team PCP, largely composed of teenagers, claimed responsibility.\n\nIndependent researcher Kevin Beaumont confirmed the data's legitimacy, calling it a massive supply chain breach due to poor AI security. The compromised versions scraped memory and exfiltrated data. In total, about 434,000 CI/CD software pipelines had credentials exposed.

Some organizations were misidentified; for example, an @siriusxm.com address belonged to subsidiary Ads Wizz, not Sirius XM itself.