Massive LiteLLM Supply Chain Attack Exposes 153GB of Stolen Credentials

Massive LiteLLM Supply Chain Attack Exposes 153GB of Stolen Credentials

First seen 13 Aug 2026, 16:49 UTC Feeds2.FeedburnerFeeds.4Sysops 79% similarity 66.0

Article Content

Browse articles
ThreatCluster

The LiteLLM supply chain attack has resulted in a significant data breach, with a 153GB archive containing 433,909 files, including sensitive credentials from 2,488 corporate domains. Affected companies include major players like AWS, Samsung, Cisco, and Salesforce. Hudson Rock analyzed the data and revealed that 118,829 CI runner dumps are included, raising concerns about the usability of exposed credentials. This attack has impacted over 2,500 organizations and 434,000 CI/CD pipelines, indicating a widespread security risk. The breach was first reported in March 2026, and the newly surfaced data suggests that the credentials may still be active. Hudson Rock is leveraging this information for a global ethical disclosure effort.

Key Points: • 153GB of sensitive data stolen in the LiteLLM supply chain attack. • The breach affects 2,488 corporate domains, including major companies. • Exposed credentials may still be usable, posing ongoing security risks.

ThreatCluster AI How this analysis works

Timeline

2026-03-01
LiteLLM supply chain attack reported
The LiteLLM supply chain attack was first identified, affecting numerous organizations and CI/CD pipelines.
Feeds.4Sysops
2026-08-13
153GB of stolen credentials surfaced
A massive archive containing sensitive data linked to thousands of corporate domains was disclosed, revealing the scale of the breach.
Feeds2.Feedburner

Community

Browse all →

Tracked Entities in This Story