loader image
LiteLLM With 95 Million Downloads Compromised

TeamPCP hackers have compromised the litellm Python package, a tool with over 95 million monthly downloads, used to route requests across various large language model providers. Cybersecurity firms Endor Labs and JFrog discovered a sophisticated backdoor in versions 1.82.7 and 1.82.8 of the package on the Python Package Index (PyPI). The threat actors injected malicious code into these versions, circumventing the clean upstream GitHub repository.

The code embedded within the package initiates a three-stage attack, targeting system credentials such as SSH keys, cloud provider tokens, and cryptocurrency wallets. This attack also exploits Kubernetes environments by deploying privileged containers. The persistent backdoor, disguised as a system telemetry process, continuously communicates with a command-and-control server.

TeamPCP has intensified a series of supply chain attacks, infecting GitHub Actions and Docker Hub. Organizations using litellm should audit their environments immediately. Discover the full report and learn how to protect your assets.

LiteLLM PyPI Package With 95 Million Downloads Compromised by TeamPCP Hackers

Write a Reply or Comment

Your email address will not be published. Required fields are marked *