logo

95 Million Downloads Hijacked: The LiteLLM PyPI Backdoor Targeting AI Developers

ID: dc4bc255-dd6a-5f9b-80ce-ba83d904c212

STIX ID: report--dc4bc255-dd6a-5f9b-80ce-ba83d904c212

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

A supply-chain compromise of the LiteLLM PyPI package (versions 1.82.7 and 1.82.8) delivered a multi-stage backdoor that executes on import and — via a .pth persistence file — on any Python invocation; the payload harvests credentials, targets Kubernetes clusters (deploying privileged pods), installs a systemd backdoor (sysmon.service), and exfiltrates encrypted data to attacker-controlled domains, and the activity is attributed to the threat actor "TeamPCP".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.