Top LLM PyPl Package Compromised to Steal User Credentials – Here’s What We Know


  • Popular Python package LiteLLM compromised in supply chain attack
  • Malicious updates (v1.82.7, v1.82.8) implemented TeamPCP Cloud Stealer infostealer
  • Attack Harvested Cloud Credentials, Kubernetes Secrets, Wallets; users are encouraged to rotate tokens and revert to secure versions

A hugely popular Python package called LiteLLM was compromised and used to deploy an infostealer malware to hundreds of thousands of devices.

LiteLLM is a lightweight API layer that lets users call multiple AI models (like OpenAI, Anthropic, etc.) through one unified interface. It has more than 40,000 stars and more than 30,000 commits.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top