AI supply chain attack puts over 2,500 organizations at risk

45 minutes ago 1



Homepage > News > Business > AI supply chain attack puts over 2,500 organizations at risk More than 2,500 organizations worldwide have been identified as potentially affected by a major artificial intelligence (AI) supply chain incident involving the open-source tool LiteLLM, putting credentials that could grant attackers access to critical business systems at risk, according to a new report from AI risk management firm CloudSEK. Hackers weaponize LiteLLM AI breach threatens critical sectors Attackers access critical keys FBI flags ongoing TeamPCP threat Hackers set sights on AI infrastructure, supply chain The incident In March, a cybercriminal group known as ‘Team PCP’ compromised LiteLLM, a widely used open-source tool that helps applications connect to AI models, by inserting infostealer malware directly into the LiteLLM library (a Python software repository). The cybercriminal group compromised trusted software distribution channels by injecting malicious code into legitimate packages, thereby modifying software components. This allowed them to push trojanized updates that appeared normal but secretly installed credential-stealing malware and backdoors, giving the att...

Read Entire Article