logo

SentinelOne autonomous detection blocks trojaned LiteLLM triggered by Claude Code

ID: f874b995-1d26-5b7c-b29a-b0f8de0274e0

STIX ID: report--f874b995-1d26-5b7c-b29a-b0f8de0274e0

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

SentinelOne reports it automatically blocked a supply-chain attack involving trojanized LiteLLM packages that executed obfuscated Python code and an infostealer, established persistence via a systemd user service (~/.config/systemd/user/sysmon.service and ~/.config/sysmon/sysmon.py), contacted a C2 server on delayed intervals to evade sandboxing, and expanded by creating privileged Kubernetes pods to deploy backdoors; the campaign was delivered via compromised maintainer credentials (from tools like Trivy) and was even triggered by an AI coding assistant (Claude Code), highlighting risks of AI agents with system-level access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.