Cybersecurity & Privacy — 2026-03-25

Supply Chain Attack on LiteLLM Python Package Exposes 3.4M Daily Downloads to Credential Harvesting

Threat actor TeamPCP published backdoored versions of the LiteLLM Python package (v1.82.7 and v1.82.8) on PyPI after stealing maintainer credentials via a prior compromise of the Trivy security scanner GitHub Action. The malicious payload harvested SSH keys, AWS/GCP/Azure credentials, Kubernetes configs, and database passwords from infected hosts. LiteLLM averages 3.4 million daily downloads. The tainted packages were live for approximately three hours before PyPI quarantined them. The attack was part of a broader campaign also targeting Checkmarx KICS.

Analysis
The attack chain (Trivy compromise to PyPI credential theft to LiteLLM backdoor) demonstrates how a single compromised CI/CD dependency can cascade into a mass-exposure event affecting 3.4M daily downloads. LiteLLM is used as a middleware layer in AI/LLM pipelines, meaning compromised credentials could include API keys for OpenAI, Anthropic, and cloud provider accounts. Organizations running AI inference pipelines should audit for the specific malicious .pth file indicator.
3 sources
  1. How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM - Snyk
  2. TeamPCP Supply Chain Attack Campaign Targets Trivy, Checkmarx (KICS), and LiteLLM - Arctic Wolf
  3. Trojanization of Trivy, Checkmarx, and LiteLLM solutions - Kaspersky

View in full brief →

UNCLASSIFIED // OPEN SOURCE