Skip to content

LiteLLM

Disclosed Mar 24, 20266 months agoUnverified

Malware slipped into popular LiteLLM AI gateway package stole developer credentials

Credential-stealing malware entered the LiteLLM open source AI gateway through a compromised dependency and harvested logins from machines that installed it, spreading to further packages. The project is downloaded up to 3.4 million times a day, and the campaign was attributed to TeamPCP.

What is known

People affectedNot stated in the sources we have
DisclosedMar 24, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofTrivy (2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMar 24
ResearchtotalMar 26

Same campaign

History of this record
  • 2026-09-25 · summary: Versions 1.82.7 and 1.82.8 of the popular LiteLLM AI gateway package on PyPI were trojanized to steal cloud credentials, SSH keys, Kubernetes tokens and environment files. TeamPCP claimed data from hundreds of thousands of devices, with sou to Credential-stealing malware entered the LiteLLM open source AI gateway through a compromised dependency and harvested logins from machines that installed it, spreading to further packages. The project is downloaded up to 3.4 million times a · seed source
  • 2026-09-25 · title: LiteLLM PyPI package backdoored by TeamPCP to steal AI developer secrets to Malware slipped into popular LiteLLM AI gateway package stole developer credentials · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about LiteLLM

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.