216.73.217.22

Malicious PyPI Package - LiteLLM Supply Chain Compromise

· Published 25/03/2026 10:38 · Modified 27/03/2026 00:08

Export JSON

Essential information

Published
25/03/2026 10:38
Modified
27/03/2026 00:08
Tags
2026-03-25 cloud credentials litellm pypi supply-chain
Related entities
1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 others

Description

A malicious supply chain attack has been discovered in the Python Package Index package version 1.82.8. The compromised package contains a malicious .pth file that executes automatically when the Python interpreter starts, without requiring explicit import. This file, located in site-packages/, exfiltrates sensitive information including environment variables, SSH keys, and to an attacker-controlled server. The payload is double base64-encoded to evade basic static analysis. administrators have quarantined the project to limit its spread. Users are advised to check for the malicious file, rotate all potentially exposed credentials, and audit their publishing process. The attack is attributed to TeamPCP and is actively exploited in the wild.

External references