Skip to main content

Share story

Security

LiteLLM Supply Chain Attack: What Happened and How to Respond

LiteLLM Supply Chain Attack: What Happened and How to Respond Image: Primary
A threat actor known as TeamPCP compromised the PyPI publishing credentials for LiteLLM on March 24, 2026. The group published backdoored versions 1.82.7 and 1.82.8 that contained malicious code in the wheel files. The library routes requests to large language model providers and averages 95 million monthly downloads. Version 1.82.6 is the last release known to be unaffected. The breach started with the compromise of the Trivy scanner in LiteLLM's CI/CD pipeline between March 19 and 23. Attackers exfiltrated PyPI tokens and used them to upload the malicious packages. At 10:39 a.m. they released version 1.82.7 with a payload in proxy_server.py. Version 1.82.8 followed at 10:52 a.m. and introduced execution via the litellm_init.pth file on interpreter start. Security researcher Callum McMahon opened GitHub issue 24512 at 11:48 a.m. after observing a fork bomb crash on his development machine. The attacker closed the issue and flooded it with bot comments at 12:44 p.m. PyPI administrators responded at 1:38 p.m. by quarantining the package, blocking downloads, and removing the bad versions. The attack reached developer and production environments rather than staying limited to build systems. The malware performs a three stage attack after installation. It harvests credentials from environment variables and files including those for OpenAI, Anthropic, Azure, and AWS or GCP. In Kubernetes environments it seeks lateral movement using service account tokens. It then installs a systemd backdoor for persistence and beaconing to a TeamPCP command and control server. Users should check installed versions with pip show litellm and look for upgrades since March 24. High memory usage from the fork bomb serves as a behavioral indicator. Mitigation requires downgrading to 1.82.6, clearing CI/CD caches, auditing systemd services, and rotating all LLM and cloud credentials.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Cycode and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

Infrastructure Products
Infrastructure Products

Microsoft offers rollback for Windows desktop loading fault

Microsoft has confirmed that updates beginning with its August 2026 preview release can leave some users with a black screen after sign-in or cause Windows Explorer to crash. The problem mainly affects Azure Virtual Desktop hosts ...

Products Infrastructure
Products Infrastructure

DLSS 5 test finds higher power draw and connector heat on RTX 5090

Enabling Nvidia's DLSS 5 raised power draw through a GeForce RTX 5090 Founders Edition's 16-pin connector from 582.7W to 646.7W in tests by Korean outlet QuasarZone, Tom's Hardware reports. The connector reached 91.7 degrees Celsi...

AI Policy
AI Policy

Pentagon seeks $30.3 million for AI-based lie detector program

The Pentagon is seeking $30.3 million over five years for a program to develop AI-based scoring and contactless sensing for lie detection, MIT Technology Review reports, citing a Defense Department budget request. The proposed Pol...