logo

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

ID: 53d186bc-fb59-52b6-ab7c-a4aaa823d54d

STIX ID: report--53d186bc-fb59-52b6-ab7c-a4aaa823d54d

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-08-17

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

Resecurity and reporting describe a supply-chain attack where maintainer credentials for the LiteLLM project were compromised and malicious PyPI package versions (1.82.7, 1.82.8) were published by the threat actor 'TeamPCP' using the SANDCLOCK credential-stealer, exposing cloud and CI/CD credentials across 2,038 repositories and affecting thousands of organizations across technology, finance, healthcare and other sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.