logo

Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens

ID: 92571675-c265-5058-8225-e2cd85c6b2ae

STIX ID: report--92571675-c265-5058-8225-e2cd85c6b2ae

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-03-24

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Endor Labs and BleepingComputer report that the TeamPCP group compromised the LiteLLM PyPI package by publishing malicious versions 1.82.7 and 1.82.8 which execute a base64-encoded payload on import; the payload deploys a credential-stealing infostealer, attempts lateral movement in Kubernetes, installs persistent backdoors (including a .pth file and a systemd user service), bundles stolen secrets into an encrypted archive (tpcp.tar.gz) and exfiltrates them to attacker-controlled infrastructure. Organizations are advised to check for the malicious versions, rotate exposed credentials, search for persistence artifacts and suspicious files, and review Kubernetes clusters and outbound traffic to known attacker domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.