‼️🚨 BREAKING: Security researchers have uncovered all of those who fell victim to the LiteLLM supply chain attack by obtaining its archive: 153GB holding 433,909 files from 2,488 organisations. According to Hudson Rock and CloudSEK, victims include Nvidia, AWS, Samsung, Boeing, Intel and more. This is one of the biggest hits by TeamPCP yet. The archive contains 118,829 CI/CD runner dumps attributed to corporate domains, with signing secrets and AI provider API keys sitting in plaintext.
If you ran LiteLLM 1.82.7 or 1.82.8, assume every secret in that environment is burned.
- Local llm is the only way to escape from this kind of supply chain attack