logo

AI Infrastructure LiteLLM Supply Chain Poisoning Alert

ID: dfce2688-0aec-5137-b7a5-6b3ca101c38a

STIX ID: report--dfce2688-0aec-5137-b7a5-6b3ca101c38a

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: NSFOCUS

...
...

NSFOCUS warns that the TeamPCP group performed a supply-chain poisoning of LiteLLM (PyPI versions 1.82.7 and 1.82.8) by compromising the Trivy scanner and abusing GitHub Actions to publish malicious wheels; the payloads steal credentials (SSH, cloud, K8s tokens, SSL keys, crypto wallets), deploy privileged Kubernetes pods for lateral movement, and install persistent systemd backdoors, with IOCs and mitigation steps provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.