LiteLLM Supply Chain Attack Exposes Critical Credentials
ID: 2ac6bca7-a4f7-5e50-9854-ff0e48a17ebb
STIX ID: report--2ac6bca7-a4f7-5e50-9854-ff0e48a17ebb
Feed Name: ThreatCluster
Threat Score
On 2026-03-24, two versions of the widely used LiteLLM package on PyPI (1.82.7 and 1.82.8) were maliciously published and delivered credential-stealing payloads that targeted SSH keys, cloud credentials, and Kubernetes secrets; the incident is attributed to the TeamPCP actor and exploited a Trivy scanner vulnerability, with version 1.82.8 using a .pth file to force automatic execution—raising significant supply-chain and scale concerns and prompting security advisories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
