logo

How GitGuardian Enables Rapid Response to the LiteLLM Supply Chain Attack

ID: d0472c10-1ca3-5f68-8c21-91a580d2f81a

STIX ID: report--d0472c10-1ca3-5f68-8c21-91a580d2f81a

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Guillaume Valadon

...
...

**Executive summary:** GitGuardian reports that TeamPCP poisoned LiteLLM PyPI packages (v1.82.7 and v1.82.8) with infostealer malware that harvested developer secrets (SSH keys, cloud credentials, API tokens, Docker configs and crypto-related data), provides IOCs and detection commands, and outlines rapid response and remediation steps including local scanning with ggshield, CI/CD audits, and secret rotation procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.