A massive supply-chain attack compromised Terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The breach occurred during a 40-minute window in March through compromised versions of LiteLLM, an open-source AI development tool, which was infected via a prior attack on the Trivy vulnerability scanner. The TeenAGE Group (TeamPCP) claimed responsibility, with researchers corroborating the authenticity of the leaked data.
Background
LiteLLM is a widely used open-source proxy tool that simplifies AI model integration for developers. Supply-chain attacks have become an increasingly common vector for large-scale breaches as attackers target trusted software dependencies.
- Source
- Ars Technica
- Published
- Aug 13, 2026 at 05:43 AM
- Score
- 8.0 / 10