Supply Chain Incident
LiteLLM PyPI package compromise through stolen CI/CD credentials
Malicious LiteLLM versions 1.82.7 and 1.82.8 were published to PyPI with code not present in the upstream repository, exposing Python users and AI pipelines to credential theft.
Evidence-Gated Propagation
Propagation Timeline
- Packageaquasecurity/trivy-actionCausalReleaselitellm@1.82.7
pkg:pypi/litellm@1.82.7Snyk reports TeamPCP published the backdoored LiteLLM versions after obtaining maintainer PyPI credentials through the prior Trivy compromise.
- Packageaquasecurity/trivy-actionCausalReleaselitellm@1.82.8
pkg:pypi/litellm@1.82.8Snyk reports TeamPCP published the backdoored LiteLLM versions after obtaining maintainer PyPI credentials through the prior Trivy compromise.
Affected Packages
Affected Releases
- litellm@1.82.7pkg:pypi/litellm@1.82.7 · published 2026-03-24Release
- litellm@1.82.8pkg:pypi/litellm@1.82.8 · published 2026-03-24Release
Repositories
Organizations
Maintainers
No structured records.
Threat Actors
Campaigns
Build Systems
- GitHub Actions
Distribution Channels
- PyPI
Compromised Accounts
- LiteLLM PyPI publishing credentials
Connected Entities
- BerriAIOrganization
- BerriAI/litellmRepository
- GitHub ActionsBuild System
- litellmPackage
- LiteLLM PyPI publishing credentialsCompromised Account
- litellm@1.82.7Release
- litellm@1.82.8Release
- PyPIDistribution Channel
- TeamPCPThreat Actor
- TeamPCP Multi-Ecosystem Supply Chain CampaignCampaign
Attribution Evidence
Snyk and Trend Micro report LiteLLM as part of the TeamPCP campaign and tie it to credentials obtained through the Trivy compromise.
LiteLLM is modeled as a downstream node in the TeamPCP multi-ecosystem supply-chain campaign.
References
- Security Update: Suspected Supply Chain IncidentLiteLLM · 2026-03-24
- How a poisoned security scanner became the key to backdooring LiteLLMSnyk · 2026-03-25
- TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises LiteLLMEndor Labs · 2026-03-24
- Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain CompromiseTrend Micro · 2026-03-25