LiteLLM supply chain attack: an explainer for identity pros
ID: 6cdc3577-f3c1-5119-b7d6-8630334b4564
STIX ID: report--6cdc3577-f3c1-5119-b7d6-8630334b4564
Feed Name: Threat Intelligence | Blog | Okta
Threat Score
On March 24, 2026 threat actor TeamPCP published malicious LiteLLM PyPI package updates (versions 1.82.7 and 1.82.8) that installed a persistent infostealer on affected systems; the payload collected environment variables, SSH/Git/CI and cloud credentials, configuration files and host details and exfiltrated compressed data to attacker-controlled servers during a ~5.5-hour window, potentially impacting hundreds of thousands of users who upgraded via PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
