LiteLLM Supply-Chain Attack Threatens Over 2,500 Companies
LiteLLM is an open-source package that gives developers a unified way to connect applications with multiple large-language-model providers. Its use in software development and deployment pipelines makes a compromise particularly consequential: malware inserted into the package could spread through downstream environments, exposing API keys and other sensitive credentials rather than remaining confined to a single tool or vendor.
CloudSEK said its latest investigation found that the supply-chain attack could affect more than 2,500 companies and organizations worldwide, along with about 434,000 CI/CD workflows. Nvidia and Samsung were among the major companies identified as potentially exposed. Investigators warned that API keys and sensitive credentials may have been stolen, though confirmed misuse has not been established. The supplied report did not specify the attack date or the investigation’s publication date.
All Coverage
1 original reportsThe Backstory
The history behind this eventLiteLLM Hit by PyPI Supply-Chain Attack
LiteLLM is an open-source tool that lets developers connect to multiple large language models through a unified interface. Its PyPI package draws about 97 million downloads a month and is widely used in AI applications and CI/CD pipelines. The incident highlights how poisoning a popular open-source dependency can simultaneously expose companies’ internal systems, cloud services and digital assets to supply-chain risks.
The attack, disclosed around March 25, affected LiteLLM PyPI versions v1.82.7 and v1.82.8. Hacker group TeamPCP was accused of planting credential-stealing malware capable of collecting SSH keys, cloud and API credentials, environment variables and crypto wallet data. Reports said about 500,000 credentials were exposed. Users should immediately remove the compromised versions, inspect their runtime environments and rotate all potentially exposed credentials.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →