Skip to content
LiteLLM Supply Chain Attack Exposes Critical Credentials

LiteLLM Supply Chain Attack Exposes Critical Credentials

First seen 12 Jun 2026, 23:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 13, 2026 at 23:22 UTC
  • Two compromised LiteLLM versions on PyPI exfiltrated sensitive credentials.
  • Attack linked to TeamPCP, exploiting vulnerabilities in the Trivy scanner.
  • Malicious payloads targeted SSH keys, cloud credentials, and Kubernetes secrets.

On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a vulnerability in the Trivy open-source scanner, allowing attackers to publish malicious versions. The payloads targeted sensitive information such as SSH keys, cloud credentials, and Kubernetes secrets, exfiltrating this data to an attacker-controlled server. The malicious version 1.82.8 introduced a .pth file for automatic execution, escalating the threat. The incident highlights the risks associated with supply chain attacks in software development environments. Security advisories have been issued, and further analysis is ongoing to mitigate the impact. The LiteLLM library is widely used, with millions of downloads daily, raising concerns about the broader implications of this breach.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-03-23
Exfiltration domain registered
The domain models.litellm.cloud was registered one day before the malicious packages appeared on PyPI.
SafeDep
2026-03-24
LiteLLM package compromised
Versions 1.82.7 and 1.82.8 of LiteLLM were found to contain credential-stealing payloads.
TrendMicro
2026-03-24
Security advisory filed
A security advisory reported the malicious .pth file in version 1.82.8, not present in the source repository.
SafeDep
2026-06-12
Current analysis ongoing
Security researchers continue to analyze the impact and provide mitigation strategies for affected users.
TrendMicro

More articles in this cluster (3)

Following this threat?

Track TeamPCP, Miasma and BerriAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed