Malicious versions 1.82.7 and 1.82.8 of the widely used litellm Python package were uploaded to PyPI after attackers used compromised publishing access, turning a popular AI gateway library into a supply-chain malware delivery vehicle. Researchers and project maintainers said the tainted code was absent from the upstream GitHub repository, indicating the compromise occurred in the release pipeline or during package publication. The malware executed on import in 1.82.7, while 1.82.8 added a litellm_init.pth file that triggered on every Python interpreter startup, greatly expanding exposure even beyond direct use of the package. PyPI removed or quarantined the malicious releases, and 1.82.6 was identified as the last known clean version.
The payload harvested a broad range of secrets, including cloud credentials, SSH keys, API tokens, Kubernetes service-account tokens, database and CI/CD secrets, .env files, shell histories, TLS keys, and cryptocurrency wallet data, then encrypted and exfiltrated the data to attacker-controlled infrastructure including models.litellm.cloud. Multiple reports said the malware also attempted Kubernetes lateral movement by enumerating clusters, dumping secrets, and deploying privileged pods across nodes, while establishing Linux persistence through a disguised systemd user service that contacted checkmarx.zone for follow-on payloads. Researchers linked the intrusion with high confidence to TeamPCP, tying it to the earlier Trivy compromise and a broader campaign spanning GitHub Actions, Docker Hub, npm, OpenVSX, and PyPI; organizations that installed and ran the affected versions were urged to assume full credential compromise, rotate secrets, inspect for persistence, and review Kubernetes environments for rogue activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
One reference states LiteLLM published an official actively maintained security update on March 25, 2026. Another says package restoration occurred with new releases paused pending a supply-chain security review.
After the compromise was identified, PyPI removed or quarantined the malicious LiteLLM releases, with several references saying the packages were available only for a few hours. Some reporting also says the entire project was temporarily quarantined during response efforts.
A Hacker News post on March 24 reported suspicious behavior from newly deployed LiteLLM versions 1.82.7 and 1.82.8, including severe resource exhaustion and discovery of a base64-encoded blob in proxy_server.py. The reporter said they were escalating the issue upstream.
The malicious 1.82.8 release added a litellm_init.pth file that caused the payload to execute whenever Python started, making it more dangerous than the import-triggered 1.82.7 variant. References describe this as a significant escalation in execution and persistence behavior.
On March 24, 2026, attackers used compromised publishing access to upload trojanized LiteLLM versions 1.82.7 and 1.82.8 to PyPI. The malicious code was absent from the upstream GitHub repository, indicating compromise during or after the package build and release process.
One reference states the exfiltration domain models.litellm.cloud was registered by the threat actors on March 23, 2026, to blend in with legitimate LiteLLM traffic. The domain was later used to receive encrypted stolen data from compromised hosts.
References describe a follow-on TeamPCP supply-chain incident affecting Checkmarx components, including KICS and related extensions/actions, as part of the same broader campaign. This event is explicitly anchored as occurring on March 23, 2026.
Multiple references say TeamPCP first compromised Aqua Security's Trivy supply chain on March 19, 2026, abusing the release process to distribute a malicious Trivy version and harvest credentials from downstream CI/CD environments. Those stolen secrets were later cited as the path to the LiteLLM compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
32 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceschneier.com
Open sourcesoftwareimprovementgroup.com
Open sourceosintteam.blog
Open sourceendorlabs.com
Open sourcelinkedin.com
Open sourcebleepingcomputer.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.