LiteLLM Python Package With 95 Million Downloads Compromised by TeamPCP Hackers
ID: 81038326-1da5-541a-a595-90b6594a0b63
STIX ID: report--81038326-1da5-541a-a595-90b6594a0b63
Feed Name: cybersecurityNews.com
Threat Score
A high-impact supply-chain compromise of the widely used PyPI package "litellm" (v1.82.7 and v1.82.8) injected a stealthy backdoor that executes on import and via a .pth startup file, enabling credential harvesting (SSH keys, cloud tokens, DB credentials, wallets), Kubernetes lateral movement, systemd-based persistence, and exfiltration to attacker-controlled domains; the activity is attributed to TeamPCP and the impacted releases have been removed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
