LiteLLM Hit by PyPI Supply-Chain Attack
LiteLLM is an open-source tool that lets developers connect to multiple large language models through a unified interface. Its PyPI package draws about 97 million downloads a month and is widely used in AI applications and CI/CD pipelines. The incident highlights how poisoning a popular open-source dependency can simultaneously expose companies’ internal systems, cloud services and digital assets to supply-chain risks.
The attack, disclosed around March 25, affected LiteLLM PyPI versions v1.82.7 and v1.82.8. Hacker group TeamPCP was accused of planting credential-stealing malware capable of collecting SSH keys, cloud and API credentials, environment variables and crypto wallet data. Reports said about 500,000 credentials were exposed. Users should immediately remove the compromised versions, inspect their runtime environments and rotate all potentially exposed credentials.
All Coverage
8 original reportsThe Backstory
The history behind this eventPyTorch Deep-Learning Library Lightning Hit by Mini Shai-Hulud Supply-Chain Attack
Lightning is a deep-learning tool maintained by Lightning AI and built on PyTorch, the framework initiated by Meta. Developers install it through the Python Package Index (PyPI). Tampering with a popular package can allow malware to spread through build and model-training environments, and the incident is considered an extension of the Mini Shai-Hulud supply-chain attack.
The Lightning team confirmed that its PyPI publishing account was compromised in late April and that the attacker uploaded malicious versions 2.6.2 and 2.6.3. The incident was also added to a cybersecurity daily report's tracking list on May 7. The team has issued an advisory urging users who installed either version to remove the package, inspect their environments and rotate potentially exposed credentials. It has not disclosed the number of victims or any financial losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.