Terabytes of credentials leaked in massive supply-chain attack
Summary
Ars Technica reports terabytes of credentials exfiltrated in a supply-chain attack on LiteLLM, exposing cloud keys, repository tokens, SSH keys, Kubernetes secrets, and CI/CD pipeline credentials across more than 2,500 organizations. The incident highlights open-source supply-chain risks and the urgent need for credential rotation, revocation, and comprehensive monitoring to limit impact.