Malicious versions of the open-source AI gateway LiteLLM were uploaded to PyPI in March, exposing sensitive credentials from over 2,500 organizations to a sophisticated supply-chain attack campaign.
Key Points
- Compromised LiteLLM versions 1.82.7 and 1.82.8 were active on PyPI for 40 minutes on March 24, harvesting cloud keys, SSH keys, and database passwords.
- Threat intelligence firm CloudSEK identified potential exposure across 2,500 organizations, including major entities like NVIDIA, Cisco, and the European Commission.
- The incident is part of the broader "TeamPCP" supply-chain campaign, which also involved the compromise of the Trivy security scanner.
- Malicious code executed automatically upon Python interpreter startup, exfiltrating environment variables and secrets to an attacker-controlled domain.
- The FBI and security researchers advise organizations to rotate all credentials that were accessible on systems where the compromised packages were installed.