Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
AI Summary
Malicious versions 1.82.7 and 1.82.8 of the open-source LiteLLM package were uploaded to PyPI on March 24, 2026, and remained available for approximately 40 minutes before being quarantined. These compromised releases contained a credential-stealing payload that collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, exfiltrating them to the domain models.litellm[.]cloud. The incident is part of the broader TeamPCP supply-chain campaign, linked to the earlier compromise of Aqua Security's Trivy scanner, which allowed attackers to gain access to PyPI publishing tokens. The attack potentially exposed over 2,100 organizations, with stolen data including sensitive CI/CD secrets that remain exploitable if not rotated.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 6 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | models[.]litellm[.]cloud | Details → |
| Filename | litellm_init.pth | Details → |
| Package | [email protected] | Details → |
| Package | [email protected] | Details → |
| GitHub Repo | tpcp-docs | Details → |
| GitHub Repo | docs-tpcp | Details → |