logo

LiteLLM supply chain attack: an explainer for identity pros

ID: 6cdc3577-f3c1-5119-b7d6-8630334b4564

STIX ID: report--6cdc3577-f3c1-5119-b7d6-8630334b4564

Feed Name: Threat Intelligence | Blog | Okta

Threat Score
88/100

Date Published: 2026-03-24

Date Updated: 2026-07-16

Author: Brett Winterford

...
...

On March 24, 2026 threat actor TeamPCP published malicious LiteLLM PyPI package updates (versions 1.82.7 and 1.82.8) that installed a persistent infostealer on affected systems; the payload collected environment variables, SSH/Git/CI and cloud credentials, configuration files and host details and exfiltrated compressed data to attacker-controlled servers during a ~5.5-hour window, potentially impacting hundreds of thousands of users who upgraded via PyPI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.