Earlier this year, in March, a hacking group known as TeamPCP pulled off quite the cyber heist, compromising first the LiteLLM open source Python library, and via that…
Well, potentially everyone who uses the LiteLLM Python library; which, according to research released this week by cyber security firm CloudSEK, is quite a lot of companies.
More than 2,500, in fact.
LiteLLM, however, wasn’t the initial target, however. Trivy, an open-source security scanner, was the first point in the kill chain, which was compromised via a previously leaked authentication token that had been rotated but not completely revoked.
“LiteLLM was never attacked directly. Its [Continuous Integration] pipeline installed the Trivy scanner unpinned from the system package manager (apt), so the compromised scanner flowed into the build automatically, and that build produced and published the malicious 1.82.7 and 1.82.8 releases to PyPI,” CloudSEK said in an August 11 blog post.
“Trivy, then the build system, then the LiteLLM release: one un-revoked token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure.”
CloudSEK does make the point that not all the companies it uncovered in its reconstruction of the exposure may have actually been compromised, but the potential is certainly there, and that list is still alarmingly large list. In little more than 40 minutes, thousands of companies were exposed to compromise.
“Those exposed range from large AI companies and model providers to cybersecurity vendors, SaaS platforms, and enterprises worldwide,” CloudSEK said.
The list of potentially exposed companies includes Amazon Web Services, Airbus, Cisco, and ServiceNow as “high confidence” exposures, while other companies may include FedEx, the London Stock Exchange, Thales Group, and Epic Games. And the data that may have been stolen could easily lead – or have already led – to further downstream compromise.
“Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys could allow attackers to move far beyond the affected package,” CloudSEK said.
The company drew an apt analogy, comparing the LiteLLM breach to the targeting of rail junctions during industrial age warfare. As vital supply routes, they become targets capable of significantly impacting wider operations. AI gateways, like LiteLLM, CloudSEK said, “are becoming the junctions of digital operations”.
“The incident was not only a software supply chain breach that happened to involve an AI product. It demonstrated that compromising an AI control point can expose the identities and systems around it,” CloudSEK said.
“Future attacks are likely to target the AI layer precisely because it is connected to everything else.”
Speaking at the time of the initial breach in March, Cory Michal, CISO at application security firm AppOmni, told Cyber Daily the LiteLLM breach was "exactly the kind of cascading, transitive risk security teams worry about most".
“The big picture issue is that the software supply chain is still built on too much implicit trust and not enough immutability or verification: Organisations routinely allow third-party actions, packages, and release artifacts into build pipelines because they come from trusted vendors or popular projects, but this incident shows how fragile that model is when an upstream component is compromised.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.