Terabytes of credentials leaked in massive supply-chain attack
Terabytes of credentials stolen via compromised AI package — 2,500 users exposed in one of the largest supply-chain breaches targeting the AI ecosystem.

Why it matters
A major supply-chain attack on AI tooling shows the vulnerability of the rapidly-scaling agent and AI-developer ecosystem. This is not theoretical risk — credentials and secrets are actively being harvested from production deployments at scale.
The key facts
5 to know2,500 users of compromised AI package affected
Terabytes of credentials exfiltrated
Supply-chain attack vector targeting AI ecosystem
Credentials suggest production systems and integrations exposed
Published Aug 12, 2026 — recent and breaking
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: The data was scraped and exfiltrated from 2,500 users of a compromised AI package.