safedep.io LiteLLM Supply Chain Attack Exposes Critical Credentials
Article Content
- •Two compromised LiteLLM versions on PyPI exfiltrated sensitive credentials.
- •Attack linked to TeamPCP, exploiting vulnerabilities in the Trivy scanner.
- •Malicious payloads targeted SSH keys, cloud credentials, and Kubernetes secrets.
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a vulnerability in the Trivy open-source scanner, allowing attackers to publish malicious versions. The payloads targeted sensitive information such as SSH keys, cloud credentials, and Kubernetes secrets, exfiltrating this data to an attacker-controlled server. The malicious version 1.82.8 introduced a .pth file for automatic execution, escalating the threat. The incident highlights the risks associated with supply chain attacks in software development environments. Security advisories have been issued, and further analysis is ongoing to mitigate the impact. The LiteLLM library is widely used, with millions of downloads daily, raising concerns about the broader implications of this breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track TeamPCP, Miasma and BerriAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…