logo

An AI gateway designed to steal your data

ID: 91c2530b-4d11-5716-b9d9-4a884b49a90e

STIX ID: report--91c2530b-4d11-5716-b9d9-4a884b49a90e

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-29

Author: Vladimir Gursky

...
...

**Supply-chain compromise of LiteLLM (PyPI) and trojanized OpenVSX/Checkmarx extensions:** attackers published malicious LiteLLM packages that executed Base64-embedded Python payloads to collect filesystem secrets, runtime AWS/ECS credentials, database and CI/Terraform/Helm configurations, and crypto wallet data, then encrypted and exfiltrated results to a C2 (checkmarx.zone); the malware also attempted Kubernetes node breakout and persistent systemd-based implants on nodes and hosts. Victims were observed globally and compromised packages have been removed from repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.