LiteLLM supply chain attack: an explainer for identity pros
ID: 803c51e3-6c1e-5d24-ba55-96821a606608
STIX ID: report--803c51e3-6c1e-5d24-ba55-96821a606608
Feed Name: Okta Threat Intelligence
## Executive summary On March 24, 2026 threat actors identified as TeamPCP published malicious versions (1.82.7 and 1.82.8) of the LiteLLM PyPI package that install a persistent infostealer triggered on Python startup; the malware harvests API tokens, SSH/Git/CI/CD/cloud credentials, keys, config files and shell history, compresses the data and exfiltrates it to attacker infrastructure. The compromise affected users who installed or upgraded LiteLLM via PyPI during a roughly 5.5-hour window and could have exposed a large number of developers and automated systems given LiteLLM's high download volume.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
