NVDA 225.30 ▲0.54%GOOGL 346.36 ▲0.82%MSFT 496.88 ▲0.90%AMD 483.01 ▲0.02%INTC 104.56 ▲3.58%TSMC 430.49 ▲0.31%AMZN 265.13 ▼0.80%META 594.97 ▲2.78%AAPL 305.26 ▲1.00%PLTR 179.01 ▲4.66%
Markets at last close

Security

Malicious LiteLLM releases exposed secrets in PyPI supply-chain attack

·1 min read

Two malicious LiteLLM releases were available on PyPI for about 40 minutes in March and included code designed to steal environment variables, SSH keys, cloud credentials, Kubernetes tokens, database passwords, and model API keys. LiteLLM identified versions 1.82.7 and 1.82.8 as compromised and said users should treat installs on March 24 from 10:39 to 16:00 UTC as suspect.

CloudSEK says a dataset built from roughly 434,000 captured files and logs maps potential exposure to more than 2,500 organizations, though the company stressed the figures are not a confirmed victim count. The public lookup labels entries by confidence, using CI runner identity signals, host details, committer domains, and repository namespaces to assess likely ownership.

The incident is tied to the wider TeamPCP supply-chain campaign involving Aqua Security’s Trivy scanner, tracked by Google as UNC6780 and by CVE-2026-33634. The FBI warned that stolen credentials could be used long after the initial compromise, and organizations are being urged to check for affected LiteLLM installs, rotate exposed secrets, and search GitHub repositories for TeamPCP indicators such as tpcp-docs or docs-tpcp.

Originally reported by thehackernews.comRead the source →
Related coverage