Tools AI Risk Radar ai-incident-0072
Incident record
Popular LiteLLM PyPI package backdoored in a supply-chain attack
- Severity
- High
- Status
- In the wild
- Type
- Poisoning
- Target
- LiteLLM
- Actor
- criminal
What happened
A group tracked as TeamPCP compromised the widely used LiteLLM Python package on PyPI and published malicious versions that harvested SSH keys, cloud credentials and other secrets from developer machines. Snyk and the project's maintainers traced it to the project's PyPI publishing token, taken out of its CI pipeline days earlier through a poisoned release of the Trivy scanner's GitHub Action that the workflow pulled unpinned; Endor Labs, which found the malicious builds, calls the exact vector unconfirmed. The package draws more than three million downloads a day. PyPI pulled both versions and suspended the whole project, the maintainers rotated their accounts and held all releases while they audited the chain, and the next clean version, 1.83.0, did not appear until 31 March 2026.
The malicious releases were 1.82.7 and 1.82.8, published thirteen minutes apart on 24 March 2026, with 1.82.6 of 22 March the last verified clean build. Twelve lines inserted into litellm/proxy/proxy_server.py harvested SSH keys, cloud tokens, Kubernetes secrets, .env files and wallet data; 1.82.8 added a .pth file that fired on any Python invocation. The payload also moved laterally by deploying privileged Kubernetes pods and installed a systemd unit that polled a command server every 50 minutes. Datadog placed LiteLLM at the end of a campaign chain running through Trivy on 19 March, npm from 20 to 22 March and Checkmarx on 23 March.
Sources
- Endor Labs: the TeamPCP campaign reaches LiteLLM on PyPI (24 March 2026)www.endorlabs.com/learn/teampcp-isnt-done
- Snyk: the poisoned security scanner behind the LiteLLM backdoor (24 March 2026)snyk.io/blog/poisoned-security-scanner-backdooring-litellm/
- Datadog Security Labs: tracing the TeamPCP supply-chain campaign into PyPI (24 March 2026)securitylabs.datadoghq.com/articles/litellm-compromised-pypi…
- LiteLLM issue 24518: the project's own compromise timeline and statusgithub.com/BerriAI/litellm/issues/24518
- PyPI: the release record for litellm (JSON)pypi.org/pypi/litellm/json
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026