Cybersecurity & Privacy — 2026-03-25
Supply Chain Attack on LiteLLM Python Package Exposes 3.4M Daily Downloads to Credential Harvesting
Threat actor TeamPCP published backdoored versions of the LiteLLM Python package (v1.82.7 and v1.82.8) on PyPI after stealing maintainer credentials via a prior compromise of the Trivy security scanner GitHub Action. The malicious payload harvested SSH keys, AWS/GCP/Azure credentials, Kubernetes configs, and database passwords from infected hosts. LiteLLM averages 3.4 million daily downloads. The tainted packages were live for approximately three hours before PyPI quarantined them. The attack was part of a broader campaign also targeting Checkmarx KICS.
Analysis
The attack chain (Trivy compromise to PyPI credential theft to LiteLLM backdoor) demonstrates how a single compromised CI/CD dependency can cascade into a mass-exposure event affecting 3.4M daily downloads. LiteLLM is used as a middleware layer in AI/LLM pipelines, meaning compromised credentials could include API keys for OpenAI, Anthropic, and cloud provider accounts. Organizations running AI inference pipelines should audit for the specific malicious .pth file indicator.
The attack chain (Trivy compromise to PyPI credential theft to LiteLLM backdoor) demonstrates how a single compromised CI/CD dependency can cascade into a mass-exposure event affecting 3.4M daily downloads. LiteLLM is used as a middleware layer in AI/LLM pipelines, meaning compromised credentials could include API keys for OpenAI, Anthropic, and cloud provider accounts. Organizations running AI inference pipelines should audit for the specific malicious .pth file indicator.