LiteLLM
Disclosed Mar 24, 20266 months agoUnverified
Malware slipped into popular LiteLLM AI gateway package stole developer credentials
Credential-stealing malware entered the LiteLLM open source AI gateway through a compromised dependency and harvested logins from machines that installed it, spreading to further packages. The project is downloaded up to 3.4 million times a day, and the campaign was attributed to TeamPCP.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 24, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys |
| Sector | AI · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Part of | Trivy (2026) |
Sources
| Source | |
|---|---|
| Popular LiteLLM PyPI package backdoored to steal credentials, auth tokensbleepingcomputer.com · News | News |
| Silicon Valley's two biggest dramas have intersected: LiteLLM and Delvetechcrunch.com · News | News |
Notices filed
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Apr 265 months ago | Supply chain | Tech | Confirmed | Unknown | |
| Mar 315 months ago | Supply chain | Tech | Unverified | Unknown | |
| Mar 276 months ago | Supply chain | Government | Confirmed | Unknown | |
| Mar 216 months ago | Supply chain | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · summary: Versions 1.82.7 and 1.82.8 of the popular LiteLLM AI gateway package on PyPI were trojanized to steal cloud credentials, SSH keys, Kubernetes tokens and environment files. TeamPCP claimed data from hundreds of thousands of devices, with sou to Credential-stealing malware entered the LiteLLM open source AI gateway through a compromised dependency and harvested logins from machines that installed it, spreading to further packages. The project is downloaded up to 3.4 million times a · seed source
- 2026-09-25 · title: LiteLLM PyPI package backdoored by TeamPCP to steal AI developer secrets to Malware slipped into popular LiteLLM AI gateway package stole developer credentials · seed source
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.