LiteLLM supply chain backdoor: malicious 1.82.7 and 1.82.8 on PyPI
On March 24, 2026, two backdoored LiteLLM versions, 1.82.7 and 1.82.8, sat on PyPI for roughly three hours. Attackers calling themselves TeamPCP stole PyPI publishing credentials via a compromised Trivy GitHub Action in LiteLLM's CI, and a litellm_init.pth file executed on every Python interpreter startup, harvesting SSH keys, cloud tokens, Kubernetes secrets and LLM API keys.
- Versions 1.82.7 and 1.82.8 were published to PyPI on March 24, 2026, 13 minutes apart
- The litellm_init.pth file ran on every Python interpreter startup in the environment
- Stolen data included SSH keys, cloud tokens, Kubernetes secrets and LLM API keys
- PyPI quarantined the entire litellm project; LiteLLM cites a roughly 40-minute window
Read next
Security