Security

LiteLLM Leak: Hudson Rock Finds 153-Gigabyte Archive of Credentials

3 min read

TL;DR Too Long; Didn’t read

Hudson Rock has made public a dataset from the LiteLLM attack that consolidates credentials from allegedly 2488 companies. The 153-gigabyte archive includes 433,909 individual files and for the first time names Samsung, ServiceNow, and Deloitte as potential targets. A free domain check shows affected companies whether their own credentials are included. According to the FBI, the credentials copied in March remain a risk for attacks.

A magnifying glass labeled Hudson Rock enlarges a torn-open shipping container labeled LiteLLM, spilling golden keys onto a file archive. Image generated with GPT Image 2

Key takeaways

  • Hudson Rock assigns a total of 118,829 CI runner dumps to 2488 company domains.
  • The archive measures 153 gigabytes and contains 433,909 individual files from the March incident.
  • Newly named are, among others, Samsung, ServiceNow, Deloitte, John Deere, and BT Group.
  • A free lookup at hudsonrock.com/litellm checks whether your own domain is affected.
  • Verified companies gain access to their own findings through the Cavalier platform.
  • The FBI continues to warn against misuse of credentials stolen in March.

The security firm Hudson Rock has evaluated and released an archive of stolen credentials from the LiteLLM attack of March 2026. The 153-gigabyte collection contains 433,909 files, which analysts attribute to 2,488 company domains – far more detail than the earlier estimate from the start of August.

Archive bundles raw data from tens of thousands of pipelines

According to Hudson Rock co-founder Alon Gal, the data comes from automated CI runner environments that were skimmed in March by the injected file litellm_init.pth. Of the 433,909 files in the archive, the firm attributes 118,829 CI runner dumps to specific company domains, while the rest still lack a clear match. The package bundles AWS access keys, Azure environment variables, Slack signing secrets, Salesforce client secrets, internal JWT tokens, database passwords, and API keys for AI providers. Also found were local configuration files such as .aws/credentials and .kube/config, plus GitLab credentials pointing to direct access to developer machines.

The original attack itself is not new: as beckmann.ai already reported, the group TeamPCP compromised the scanner Trivy in March and used it to publish two tampered LiteLLM versions on PyPI. What’s new is the scale of the raw data now under review: where the CloudSEK report from August 11 relied on matched domain lists, Hudson Rock is now publishing the underlying 153-gigabyte archive itself for scrutiny and feeding it into its own threat database, Cavalier. For comparison: the data volume is roughly equivalent to 30,000 high-resolution photos – bundled here as plain text and configuration files pulled from corporate systems.

More big-name companies now appear on the list

Beyond the six names already known from the CloudSEK report – Nvidia, Amazon Web Services, Cisco, Salesforce, Orange, and Siemens – Hudson Rock now also names Samsung, ServiceNow, S&P Global, Deloitte, John Deere, Epic Games, and British telecom group BT Group as organizations with hits in the archive. The remaining roughly 300,000 files could not yet be clearly matched to a domain, meaning the number of actually affected organizations could still grow.

Notable is the share of manufacturing and agricultural-equipment suppliers such as John Deere alongside financial firms like S&P Global and consultancies like Deloitte – industries where stolen cloud access can cause especially large follow-on damage. Consultancies in particular often hold access to their own clients’ systems, so a single compromised account can indirectly affect other organizations too.

This attribution is independently unverified: it rests on Hudson Rock’s own matching of metadata found in the dumps against known company domains, and none of the named companies has confirmed it. Security researcher Kevin Beaumont attributes the find to weak DevOps security at the affected organizations.

Affected companies can review their own data

Hudson Rock offers a free lookup at hudsonrock.com/litellm: companies enter their domain and find out whether credentials from their organization turn up in the archive. Anyone who confirms a match gains insight into their own findings through Cavalier, the platform the firm otherwise uses for its own threat analysis, as part of a global disclosure program.

Gal describes the approach as an attempt to reach affected parties directly rather than letting the raw data circulate unchecked. Hudson Rock says it regularly uses a similar process for findings from infostealer campaigns to warn companies about criminal access to their credentials.

The FBI had already warned in a flash alert in July that credentials copied in March can keep being abused in new attacks regardless of the affected software’s current status. For security teams, that means uninstalling a package does not end the risk as long as the keys copied back then have not been actively rotated. Not finding your own domain on the list is therefore no guarantee of safety either – the 2,488 matched domains represent only the portion of the archive identified so far.

What matters now is how many of the newly named corporations actually use the lookup and rotate their keys before criminals turn the credentials that have circulated for five months into new attacks. CrowdStrike recently described a similar pattern involving stolen AI access via hijacked npm packages – stolen credentials for AI services, it turns out, remain a lucrative target months after their discovery.

Frequently asked questions

Is my company automatically affected if it is mentioned in the list?

No. Hudson Rock assigns domains based on metadata in the stolen files, and there is no confirmation from the mentioned companies. A domain check of your own provides more clarity than the name mention alone.

How do affected companies get access to their data?

Through the free lookup at hudsonrock.com/litellm. Anyone who confirms a match gains insight into their own findings through the Cavalier platform as part of the disclosure program.

How does this finding differ from the CloudSEK report from August 11?

CloudSEK had named affected companies based on its own domain matching. Hudson Rock is now publishing the underlying raw data itself and adding previously unnamed companies plus additional data types such as local configuration files and GitLab credentials.

Is it enough to uninstall the compromised LiteLLM version?

No. According to the FBI, credentials copied in March remain usable regardless of software status as long as companies have not actively rotated them.

Has LiteLLM commented on the new archive?

No separate statement on the Hudson Rock archive has been issued so far. The maintainers had already replaced the compromised accounts and build chains back in March.

Sources (3)
  1. Hudson Rock: Largest AI Supply Chain Breach of 2026 – Ethical Disclosure
  2. Help Net Security: 153GB of stolen credentials surface after LiteLLM supply chain attack
  3. CyberInsider: LiteLLM breach data shows supply chain attack impacted 2,488 firms

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog