Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

  • python@lemmy.world
    link
    fedilink
    English
    arrow-up
    48
    ·
    21 hours ago

    Even better, LiteLLM does not salt their SHA256 password hashes by default. I had to make a huge fucking fuss over that fact until my org changed the configuration last month. Bet we’re in that leak, with password hashes that are easily cracked with a dictionary.

    • douglasg14b@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      6 hours ago

      Our org is doing it better by just hiding the configuration from everyone else in the org, so no one can audit it anyways 🤦

      Who knows how it’s configured.

      • python@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 hours ago

        Have you ever pressed F12? We technically weren’t allowed to see the config either, but LiteLLM literally returned a users password hash as part of the user data json in the version we were using. It was easy enough to see that it wasn’t salted.
        Another fun thing it does is that any user can see their entire teams token spend trough the network tab, even if they technically shouldn’t be allowed to do that. Oh and LiteLLM had a CVSS score 9.9 vulnerability recently where any user with any sort of write privilege (including the “privilege” to change any of your own data, like your password) could just change their own role to admin 🤷

        The pure incompetence of that software would be really funny if it wasn’t such a pain in the ass to be the person who has to convince coworkers to rotate compromised credentials…

  • ndondo@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    9
    ·
    16 hours ago

    Can anyone who works in the security space tell me if we are as cooked as I think we are?

    With ai I’m assuming any script kiddie with motivation has access to a SIGNIFICANTLY larger surface area of attacks. And sometimes I do stupid things like wait an extra few days before updating my pc/software.

    I have this suspicion that everything digital is far more vulnerable now than it ever was. But I have only surface level knowledge in the space. Is it as bleak as I think?

    • DeadDigger@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 hours ago

      Possible IT attacks are so sophisticated, that for example rowvolt uses out of os processor voltage regulation to target specific AES cycles to produce errors so the initial password can be decoded. Row Hammer is an attack where by hammering ram spaces with random numbers you can do electric but flips in adjacent ram transistors wich make the system write Infos in wrong address spaces. Both attacks are physical attacks on hardware through software and impossible to defend against. However the in nature attacks are mostly social profiling and not software related. Software related attacks are seldom in the wild. Even the attack here is basically a social engineering attack because ppl installed Maleware on their systems by their own accord.

    • SupraMario@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      14 hours ago

      Not really, lot of this is hyped up sales bullshit. The reality is that security software has been getting better and better. It’s not this ecosystem of “that matches this hash or IP” anymore. For the last decade ML has been used heavily. It doesn’t look for just the stuff it knows is bad, it looks for things that are out of place.

      End of the day…you can’t fix everything and you can’t fix your users…but the script kiddies aren’t what to worry about, it’s the large gov backed groups. Those have always been the problem.

  • kescusay@lemmy.world
    link
    fedilink
    English
    arrow-up
    53
    ·
    24 hours ago

    Isn’t this the breach that was widely reported on in March? And they’re just now disclosing the scale of the exposure?

    • screaming in digital@lemmy.ml
      link
      fedilink
      English
      arrow-up
      104
      ·
      24 hours ago

      even better…

      These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

  • PancakesCantKillMe@lemmy.world
    link
    fedilink
    English
    arrow-up
    38
    ·
    23 hours ago

    “‘… It’s a massive supply chain breach due to poor AI security—not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security.’”

    Do tell.

    “In many cases, researchers at CloudSEK and Hudson Rock had trouble identifying the organizations the credentials belonged to. For instance, an email address in the dump from the domain @siriusxm.com ultimately didn’t indicate a breach at the satellite broadcaster, but rather one within the infrastructure of SiriusXM subsidiary AdsWizz.”

    I was curious and looked up AdsWizz. They insert ads into digital audio among loads of other stuff. To me this is a nice example of conditions that lead to malware in ads. Especially if they still have not taken the required steps. I will keep blocking ads thankyouverymuch.

  • krashmo@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    21 hours ago

    It’s late and I’m tired so my math could be wrong but if they downloaded 195 TB in 40 minutes then the attacker is working with an internet connection that is at least 81.25 Gigabytes (not bits) per second. That isn’t a script kiddie. That’s serious business.

    • Skysurfer@slrpnk.net
      link
      fedilink
      English
      arrow-up
      35
      ·
      20 hours ago

      From what I am understanding, it was a 40 minute window when the malicious model was available to download in the repositories. After it was downloaded, they had all the time until it was detected in the organization to exfiltrate the data, which was potentially weeks or months.

    • Elvith Ma'for@feddit.org
      link
      fedilink
      English
      arrow-up
      14
      ·
      20 hours ago

      Download doesn’t necessarily mean that they dumped everything on their local PC - they could just upload everything from all those servers to an S3 bucket or whatever.

      That way the bottleneck would be either the ingress of the hyperscalers or the egress of the attacked company (which probably uses the hyperscalers anyway). I probably could also do that this way with my humble home Internet connection on a semi reliable WiFi…

  • belochka@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    20 hours ago

    Cool. Proper devops like in ads. Just those people I compare myself to when having impostor syndrome trips.

    I mean, these things happen, that’s just bitterness.

  • Zarajevo@feddit.org
    link
    fedilink
    English
    arrow-up
    10
    ·
    20 hours ago

    AI is boosting productivity for hackers and criminals as well, maybe the net sum of good improvement boost will be about zero after trillions of dollars invested

  • Zarobi@aussie.zone
    link
    fedilink
    English
    arrow-up
    3
    ·
    17 hours ago

    I opened the table of breaches linked at the bottom of the article. I kept clicking load more (because I was bored) and eventually got to data breaches with 0 leaked secrets but a high confidence of leakage? I’m confused what that means. How can there be a leak of 0 things?