Security Alert: Malicious LiteLLM Versions Expose Critical Credentials on PyPI

Summary: The popular Python package LiteLLM was compromised on PyPI, with malicious versions 1.82.7 and 1.82.8 stealing cloud credentials, SSH keys, and Kubernetes secrets.

On March 24, 2026, the widely-used LiteLLM Python package was compromised on PyPI. Versions 1.82.7 and 1.82.8 included malicious code designed to harvest cloud credentials, SSH keys, and Kubernetes secrets. Users who updated their environments with these versions should assume that sensitive data has been compromised.

The breach originated from a supply chain attack by the TeamPCP threat actor, which also targeted Trivy and KICS. The malware included a credential harvester and a Kubernetes lateral movement toolkit, enabling persistent backdoor access. This sophisticated campaign targets high-value credentials typically concentrated in widely adopted packages within AI ecosystems.

Trend Micro Research identified this issue after reports from multiple security vendors, including Endor Labs and JFrog. While the affected versions have been removed from PyPI, the potential damage to users' environments is significant if not addressed promptly. Engineers are advised to immediately delete the compromised package, rotate credentials across their teams, and conduct thorough security audits.

The incident highlights the critical need for robust dependency management practices in AI infrastructure to prevent unauthorized access to sensitive data.

Key facts

  • The popular Python package LiteLLM was compromised on PyPI with malicious versions 1.82.7 and 1.82.8.
  • Malicious code harvested cloud credentials, SSH keys, and Kubernetes secrets from affected environments.
  • The breach is linked to TeamPCP, who also targeted Trivy and KICS.

Why it matters

This breach underscores the importance of vigilant supply chain security and continuous monitoring to protect against unauthorized access to critical data in AI systems. It serves as a stark reminder of the potential vulnerabilities within widely used Python packages, emphasizing the need for comprehensive threat mitigation strategies.

X profile@trendaisecurityhttps://x.com/trendaisecurity
Embedded content for: Security Alert: Malicious LiteLLM Versions Expose Critical Credentials on PyPI