메뉴
BL
Ars Technica • 44일 전

공급망 해킹으로 수 테라바이트 자격 증명 대량 유출

IMP
9/10
핵심 요약

오픈소스 AI 개발 도구인 LiteLLM의 공급망 공격으로 인해 마이크로소프트, 아마존, 삼성전자 등 글로벌 기업들의 수 테라바이트(TB) 자격 증명이 대거 유출되었습니다. 악성코드에 감염된 버전을 다운로드한 43만 개 이상의 소프트웨어 파이프라인(CI/CD)이 40분 동안 탈취당한 것으로 확인되었으며, 이는 AI 도입을 서두르는 과정에서 보안이 소홀해진 대표적인 사례로 평가됩니다.

번역된 본문

AI 기반 소프트웨어 개발을 간소화하는 오픈소스 도구인 LiteLLM에 대한 공급망 공격으로 인해, 전 세계에서 가장 크고 민감한 조직에 속한 수 테라바이트(TB) 분량의 자격 증명이 유출되었습니다. Microsoft, Amazon, Cisco, Samsung, Salesforce는 접근 비밀 정보가 노출된 수많은 기업 중 일부에 불과합니다. 이번 사실은 화요일과 수요일에 보안 업체인 CloudSEK와 Hudson Rock에 의해 공개되었습니다. CloudSEK는 클라우드 키, 리포지토리 토큰, SSH 키, Kubernetes 시크릿, 패키지 배포 자격 증명, 환경 변수 및 AI 제공업체 키 등을 발견했으며, 이를 통해 공격자들은 2,500개 이상의 조직에 접근할 수 있다고 밝혔습니다.

단 40분이면 충분했습니다. 해당 자격 증명은 3월, 피해자들이 Python Package Index(PyPI) 리포지토리의 공식 위치에서 다운로드한 악성 버전의 LiteLLM을 사용한 40분 동안 탈취되었습니다. Hudson Rock은 입수한 195TB 분량의 파일을 분석한 후 이를 발견했다고 밝혔습니다. 두 회사 모두 정보의 출처는 밝히지 않았습니다. LiteLLM 감염 사태는 널리 사용되는 취약점 스캐너인 Trivy를 감염시킨 이전의 공급망 공격 결과로 발생했습니다. 이번 캠페인에서 감염된 다른 소프트웨어로는 KICS와 Telnyx Python SDK가 있습니다. 주로 10대로 구성되었지만 매우 유능한 범죄 집단인 TeamPCP가 이 공격의 배후라고 주장했으며, 연구원들도 이 주장이 사실이라고 확인했습니다.

독립 보안 연구원 Kevin Beaumont는 "여러 피해 기관을 통해 데이터가 진짜임을 확인했다"며, "조직 내 민감한 콘텐츠가 대량 포함되어 있다. 이는 열악한 AI 보안으로 인한 대규모 공급망 침해 사태이다. AI 자체가 위협이기 때문이 아니라, AI 출시를 서두르는 데만 집착하고 DevOps 보안을 소홀히 하는 조직들을 10대들이 농락할 수 있기 때문이다"라고 말했습니다.

감염된 4개의 소프트웨어 패키지에는 감염된 머신의 메모리에 접근하여 내용을 스크랩한 뒤 공격자가 제어하는 채널을 통해 데이터를 유출하는 코드가 포함되어 있었습니다. 유출된 데이터에는 다양한 정보가 섞여 있었습니다. 이 거대한 데이터 속에는 공급망 공격가 활성화되어 있던 40분 동안 LiteLLM을 실행한 수만 개 조직이 관리하는 소프트웨어 파이프라인의 자격 증명이 포함되어 있었습니다. 두 보안 회사는 모두, 손상된 LiteLLM 버전을 실행하여 약 43만 4,000개의 CI/CD(지속적 통합/지속적 배포) 소프트웨어 파이프라인의 자격 증명이 노출되었다고 밝혔습니다.

CloudSEK와 Hudson Rock의 연구원들은 자격 증명이 속한 조직을 식별하는 데 어려움을 겪는 경우가 많았습니다. 예를 들어, 덤프된 데이터에서 발견된 @siriusxm.com 도메인의 이메일 주소는 위성 방송사인 SiriusXM의 침해를 나타내는 것이 아니라, 자회사인 AdsWizz의 인프라 내부 침해를 의미했습니다. 연구원들이 자격 증명이 유출되었다고 확신하는 주요 기업 목록은 다음과 같습니다: Nvidia Corporation, Amazon Web Services (AWS), Samsung Electronics, Salesforce, Cisco, F. Hoffmann-La Roche, ServiceNow, Siemens, S&P Global, Airbus, John Deere, Regeneron Pharmaceuticals, London Stock Exchange Group (LSEG), Thomson Reuters, FedEx, Munich Re, MediaTek, Volkswagen, Deloitte, The Kroger Co., Siemens Energy, Thales Group, X Corp (Twitter), Zscaler, Epic Games, Orange S.A., HP, Philips, Fortum, Vodafone, Carl Zeiss, Deutsche Bahn, NGINX, BT Group, Liebherr, Krungthai Bank, Roku 등입니다.

Hudson Rock는 "많은 CI/CD 파이프라인이 일반적인 방식으로 구성되어 있다"며, "덤프된 변수에는 식별 가능한 기업 이메일이나 사용자 지정 도메인 문자열, 내부 서버 이름 없이 활성 데이터베이스 비밀번호, 제3자 API 키 및 클라우드 자격 증명이 그대로 포함되어 있습니다. 이는 현재 셀 수 없이 많은 조직이 활성 보안 위험 요소를 방치하고 있음을 의미합니다."라고 덧붙였습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations. 40 minutes is all it takes The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information. The LiteLLM compromise was the result of a previous supply-chain attack that infected the widely used vulnerability scanner Trivy. Other software infected in the campaign includes KICS and the Telnyx Python SDK . TeamPCP, a ramshackle but extremely capable gang largely made up of teenagers, took credit for the attack, and researchers have largely corroborated the claim. “I’ve confirmed the data is legit by the way, multiple victim orgs,” independent security researcher Kevin Beaumont said . “It contains a significant volume of sensitive content at orgs. It’s a massive supply chain breach due to poor AI security—not because AI is the threat, but teens can run circles around orgs obsessed with rushing out AI and poor DevOps security.” The compromised versions of all four software packages contained code that accessed the memory of infected machines, scraped its contents, and exfiltrated it through an attacker-controlled channel. The data is filled with an assortment of information. Interspersed in the wall of data are credentials to software pipelines maintained by the tens of thousands of organizations that ran LiteLLM during the 40-minute span that the supply-chain attack remained active. In all, both security firms said some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed after running the compromised LiteLLM versions. In many cases, researchers at CloudSEK and Hudson Rock had trouble identifying the organizations the credentials belonged to. For instance, an email address in the dump from the domain @siriusxm.com ultimately didn’t indicate a breach at the satellite broadcaster, but rather one within the infrastructure of SiriusXM subsidiary AdsWizz. A full list of organizations is here . The researchers had high confidence that these organizations had their credentials exposed: Nvidia Corporation Amazon Web Services (AWS) Samsung Electronics samsung.com Salesforce, Inc. Cisco Systems, Inc. F. Hoffmann-La Roche AG ServiceNow Siemens AG S&P Global Airbus US Space & Defense John Deere Regeneron Pharmaceuticals, Inc. London Stock Exchange Group (LSEG) Thomson Reuters FedEx Munich Remunichre.com MediaTek Inc. Volkswagen AG Deloitte The Kroger Co. Siemens Energy Thales Group X Corp (Twitter) Zscaler, Inc. Epic Games Orange S.A. HP Inc. Philips Fortum Oyj Vodafone Group Plc Carl Zeiss AG Deutsche Bahn AG NGINX, Inc. BT Group Liebherr Krungthai Bank Public Company Limited Roku, Inc. “Many CI/CD pipelines are configured generically,” Hudson Rock said. “The dumped variables contain active database passwords, third-party API keys, and cloud credentials without any identifiable company email, custom domain string, or internal server name. This means countless organizations currently have active secrets sitting in this database, completely unaware of their exposure.” Welcome to the new world of supply-chain attacks Both firms are urging all organizations that used the compromised versions of LiteLLM—particularly those listed in the high-confidence section of the list—to thoroughly rotate all credentials in their pipelines. Hudson Rock instructed any organization that uses any AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to immediately audit their environment for versions 1.82.7 and 1.82.8 of LiteLLM, the two compromised versions of the software. The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering. As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage. Update: There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported : These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos. Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet. “The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.” Post updated to add image. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 12 Comments