Sources
LiteLLM v1.82.8 Compromised: TeamPCP Supply Chain Attack Exfiltrates SSH Keys, Cloud Credentials, and Crypto Wallets
LiteLLM versions 1.82.7 and 1.82.8 published to PyPI on March 24 contained a malicious .pth file that executes automatically on every Python process startup, dumping environment variables, querying cloud metadata endpoints (IMDS), and exfiltrating SSH keys, cloud credentials, and crypto wallets encrypted with AES-256-CBC to a lookalike domain. The attack is attributed to TeamPCP, the same threat actor behind the Trivy GitHub Action compromise on March 19, who stole PyPI credentials via LiteLLM's CI/CD pipeline. The package has 97 million monthly downloads and the malicious versions were available for approximately three hours before PyPI quarantine.
↳ Follow the thread