Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the companies whose access secrets were exposed in a supply-chain attack on LiteLLM. This open source tool streamlines AI-driven software development, yet it became the vector for a breach that released terabytes of credentials. Security firms CloudSEK and Hudson Rock published the findings on Tuesday and Wednesday, revealing a 195TB file containing cloud keys, repository tokens, SSH keys, Kubernetes secrets, and AI provider keys. These artifacts could allow attackers to gain access to more than 2,500 organisations. The data was extracted during a 40-minute window in March when victims downloaded compromised versions of LiteLLM from the official Python Package Index repository. Neither firm identified the source of the stolen information.
The incident matters because it highlights how dependencies in the AI stack can compromise enterprise security without direct interaction with the victim’s network. An attacker only needed to inject malicious code into a popular package to harvest secrets from thousands of environments simultaneously. The scale of the leak suggests that even high-profile corporations rely on tools that may not be fully audited for supply-chain integrity. This breach forces a re-evaluation of trust in third-party libraries that manage critical infrastructure like CI/CD pipelines and cloud authentication.
* The attack exploited the Python Package Index repository directly
* Hudson Rock obtained the 195TB file through ethical disclosure
* No specific actor or nation has been identified as the perpetrator




