LiteLLM Supply Chain Attack Hits 96 Million Monthly Downloads
TeamPCP sought publishing access to LiteLLM's PyPI pipeline via a compromised Trivy scanner. They obtained the PYPI_PUBLISH token and poisoned versions 1.82.7–1.82.8, harvesting SSH keys, cloud tokens, and Kubernetes secrets from every installation during a 40-minute window. The malware named its archive tpcp.tar.gz, which is less operational security than it sounds.
Severity: Unrated · Category: Supply Chain
Impact: Credential exfiltration across AI agent ecosystem
Source: LiteLLM Advisory · Kaspersky · Snyk · Trend Micro
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.