logo

Supply chain attack hits widely-used AI package, risks impacting thousands of companies

ID: 310cc92b-ae74-5ad1-a4ba-df8a7e10c1b1

STIX ID: report--310cc92b-ae74-5ad1-a4ba-df8a7e10c1b1

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-03-25

Date Updated: 2026-05-01

...
...

LiteLLM, a widely used open-source Python package, was compromised when attackers published malicious versions on PyPI that exfiltrate cloud credentials, API keys and cryptocurrency wallets and install a persistent downloader; the malicious uploads (v1.82.7 and v1.82.8) were available for at least two hours and could have impacted many cloud environments given the package's popularity. Security researchers attribute the campaign to a group calling itself TeamPCP and warn that exposed credentials should be treated as potentially compromised due to the risk of broader downstream exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.