litellm data exfiltration
there seem to be recent public disclosure of "hacked" companies, >2000 of them using litellm which had a security issue recently 1, 2
while the issue itself is problematic and shows how quickly supply chain attacks or "get a quick api" into your network (litellm offers to stream multiple llm providers as a proxy) - I see a huge difference in the reporting
- hudsonrock looks like they try to squeeze out as much advertising as possible (biggest hack ever...) and showing "brandname.tld/robots.txt" as hacked employee credentials 3
- cloudsek just helps you quickly identifying the issue without overadvertising their capabilities 4
- https://www.heise.de/news/LiteLLM-Angriff-Mehr-als-2500-Unternehmen-betroffen-11412654.html ↩
- https://www.golem.de/news/nach-supply-chain-angriff-riesiges-datenleck-betrifft-unzaehlige-grosse-konzerne-2608-211886.html ↩
- https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure ↩
- https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines ↩