LiteLLM Python package hit by network compromise linked to TeamPCP
Incident
Summary
Hide ▲
Show ▼
The LiteLLM PyPI supply-chain incident linked to TeamPCP involved malicious 1.82.7 and 1.82.8 releases that could steal cloud keys, SSH keys, Kubernetes tokens, and other secrets from installed systems. CloudSEK later published a lookup built from roughly 434,000 files that maps potential exposure to more than 2,500 organizations, but it said the dataset reflects captured loot and log files rather than confirmed credential use. The compromise also overlaps with the wider Trivy-related campaign tracked as CVE-2026-33634, and responders continue to advise rotating any secrets accessible during the exposure window. The malicious packages were live on March 24 for about 40 minutes before PyPI quarantined them, and LiteLLM told users to treat installs that day up to 16:00 UTC as suspect. Version 1.82.8 added `litellm_init.pth`, which can trigger code at Python startup, while the payload also used `litellm/proxy/proxy_server.py` to harvest environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords before sending data to `models.litellm[.]cloud`. CloudSEK said its public lookup is筛
Related Happenings
Xanadu hit by network compromise
Incident
H score34
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
About this happening:
Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configura...
Xanadu hit by network compromise
IncidentAbout this happening: Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configura...
Claude-built malicious Python package on PyPI
Malware Activity
H score14
First: 31.07.2026 03:57
Last: 31.07.2026 03:57
Sources 1
About this happening:
A Claude-built malicious Python package was uploaded to PyPI and executed on 15 real systems, creating a live malware delivery chain before registry defenses removed i...
Claude-built malicious Python package on PyPI
Malware ActivityAbout this happening: A Claude-built malicious Python package was uploaded to PyPI and executed on 15 real systems, creating a live malware delivery chain before registry defenses removed i...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor Meta
H score67
First: 03.07.2026 14:30
Last: 03.07.2026 14:30
Sources 1
About this happening:
Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor MetaAbout this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Operation Navy Ghost PyPI supply-chain campaign
Campaign
H score26
First: 01.07.2026 00:02
Last: 01.07.2026 00:02
Sources 1
About this happening:
The Operation Navy Ghost campaign has targeted Python developers building Telegram bots through trojanized Pyrogram forks, creating a supply-chain path to compromi...
Operation Navy Ghost PyPI supply-chain campaign
CampaignAbout this happening: The Operation Navy Ghost campaign has targeted Python developers building Telegram bots through trojanized Pyrogram forks, creating a supply-chain path to compromi...
Timeline
-
12.08.2026 11:04 1 articles · 13d ago
CloudSEK maps LiteLLM compromise exposure to thousands of organizations
Victim Impact UpdateCloudSEK published a public lookup tying the TeamPCP-linked LiteLLM compromise to roughly 434,000 captured files and potential exposure across more than 2,500 organizations, including Checkmarx, Mercor, a European Commission AWS account, NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp; the company said the material came from captured loot and log files and that the listings indicate exposure rather than confirmed credential use.
Show sources
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations — thehackernews.com — 12.08.2026 11:04
-
25.03.2026 00:29 2 articles · 5mo ago
Malicious LiteLLM releases deploy import-time infostealer
Technical Analysis UpdateThreat actors compromised the LiteLLM project on PyPI and published malicious versions 1.82.7 and 1.82.8 that execute a hidden base64 payload when litellm/proxy/proxy_server.py is imported. Version 1.82.8 also drops litellm_init.pth so the code can run when Python starts, and the payload installs TeamPCP Cloud Stealer, a persistence script, and a systemd user service that supports encrypted exfiltration to models.litellm[.]cloud.
Show sources
- Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack — www.bleepingcomputer.com — 25.03.2026 00:29
- How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers — thehackernews.com — 06.04.2026 14:45
-
25.03.2026 00:29 1 articles · 5mo ago
TeamPCP-linked LiteLLM PyPI compromise publicly disclosed
Initial DisclosureTeamPCP is linked to the LiteLLM PyPI compromise and to the earlier Aqua Security Trivy vulnerability scanner breach, with cascading compromises reaching Aqua Security Docker images, Checkmarx KICS project, and LiteLLM. The attack was claimed to have stolen data from hundreds of thousands of devices, and exposed credentials were urged to be rotated immediately.
Show sources
- Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack — www.bleepingcomputer.com — 25.03.2026 00:29