Hackers attack LiteLLM and steal data from 2,500 of the world’s largest companies

Hackers attack LiteLLM and steal data from 2,500 of the world’s largest companies

More than 2,500 organizations had their data stolen due to an attack on the software supply chain of the LiteLLM project. Victims include Cisco, Samsung, Salesforce and Amazon Web Services, as well as Airbus US Aerospace & Defense, Thales Group, Deutsche Bahn, Munich Re and London Stock Exchange Group.

    Image source: Towfiqu barbhuiya / unsplash.com

Image source: Towfiqu barbhuiya / unsplash.com

LiteLLM, an open source gateway that converts API calls for over a hundred large language models into a single OpenAI-compatible format, was not directly compromised as a result of the attack – the direct target of the attack was the Aqua Security Trivy security module, which scans for vulnerabilities. The hack was carried out by TeamPCP hackers: a modified Trivy package was then loaded into LiteLLM without authentication, allowing the attacker to gain administrator rights on the server and install malware.

The credentials and secrets leaked by this malware are far more valuable than the company information itself: SSH and cloud resource keys, Kubernetes tokens, environment variables, repository publishing tokens, and AI vendor keys. CloudSEK and Hudson Rock experts determined that the attack was launched on March 24, but five months after the incident, the problem has still not been resolved. Hudson Rock studied 195 TB of stolen data dumps and released 153 GB of material archives; according to CloudSEK, 2,500 company resources and 434,000 CI/CD pipelines (software development projects) were compromised. Both companies have launched domain verification tools so that affected organizations can check the extent of their vulnerabilities online.

Although the companies claim to have replaced the credentials, some of the leaked keys are still valid today. There is still no guarantee that these organizations will scrutinize the mechanics of their AI systems, although this may compromise the privacy of these organizations and their customers.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version