A supply chain attack against LiteLLM resulted in the theft of a 153GB archive containing credentials and sensitive data from thousands of corporate domains, including AWS and Samsung. The stolen data, comprising over 433,000 files, is now being used for a global ethical disclosure effort by Hudson Rock. Specific details regarding CVSS scores, affected software versions, patches, and workarounds were not provided in the source article.
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global ethical disclosure effort,” Alon Gal, Hudson Rock’s co-founder and CTO, told Help Net Security. “We … More → The post 153GB of stolen credentials surface after LiteLLM supply chain attack appeared first on Help Net Security .