logo

LiteLLM supply chain attack: an explainer for identity pros

ID: 28dd4534-22db-5d37-876a-cc9a7cb225b5

STIX ID: report--28dd4534-22db-5d37-876a-cc9a7cb225b5

Feed Name: Okta Threat Intelligence

Threat Score
88/100

Date Published: 2026-03-24

Date Updated: 2026-08-05

Author: Brett Winterford

...
...

On March 24, 2026, the LiteLLM PyPI package was backdoored when threat actors (TeamPCP) released malicious updates that install a persistent infostealer executed on Python startup; it collects secrets (API tokens, cloud credentials, SSH/Git/CI/CD keys, database and Kubernetes secrets, SSL keys), configuration and environment data, compresses it, and exfiltrates it to attacker-controlled servers. The poisoned releases affected users who installed or upgraded via PyPI during a short window (10:39–16:00 UTC) and — given LiteLLM's high download volume — likely resulted in a large number of compromised systems and substantial data loss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.