Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

LiteLLM PyPI package compromise through stolen CI/CD credentials

Malicious LiteLLM versions 1.82.7 and 1.82.8 were published to PyPI with code not present in the upstream repository, exposing Python users and AI pipelines to credential theft.

ConfidenceHigh
Evidence LevelVendor
Attack StagePackage Publish
Source Artifact DivergenceYes
Attribution ConfidenceLikely

Evidence-Gated Propagation

Propagation Timeline

  1. Releaselitellm@1.82.7pkg:pypi/litellm@1.82.7

    Snyk reports TeamPCP published the backdoored LiteLLM versions after obtaining maintainer PyPI credentials through the prior Trivy compromise.

  2. Releaselitellm@1.82.8pkg:pypi/litellm@1.82.8

    Snyk reports TeamPCP published the backdoored LiteLLM versions after obtaining maintainer PyPI credentials through the prior Trivy compromise.

Affected Packages

Affected Releases

  • litellm@1.82.7pkg:pypi/litellm@1.82.7 · published 2026-03-24Release
  • litellm@1.82.8pkg:pypi/litellm@1.82.8 · published 2026-03-24Release

Repositories

Organizations

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • GitHub Actions

Distribution Channels

  • PyPI

Compromised Accounts

  • LiteLLM PyPI publishing credentials

Connected Entities

Attribution Evidence

References