Malicious LiteLLM Releases Expose 2,100+ Organizations
Two malicious LiteLLM releases were present on PyPI for 40 minutes in March. These releases contained credential-stealing code designed to harvest cloud keys, SSH keys, and database passwords. Threat intelligence firm CloudSEK obtained a dataset of 434,000 captured files, mapping potential exposure to over 2,100 organizations. The secrets remained.
Severity: Critical · Category: Supply Chain
Impact: Data exfiltration of cloud keys, SSH keys, Kubernetes tokens, and database passwords from over 2,100 organizations.
Source: The Hacker News · Aug 12 2026 · Original source
What Happened
Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, were present on PyPI for approximately 40 minutes on March 24, starting from 10:39 UTC. These releases contained credential-stealing code designed to harvest cloud keys, SSH keys, Kubernetes tokens, and database passwords from systems that installed them. The incident is connected to a wider TeamPCP supply-chain campaign, which also involved an attack on Aqua Security's Trivy scanner. The compromised packages were specifically engineered to collect environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, encrypting this stolen data before sending it to an attacker-controlled domain, models.litellm[.]cloud, which is unrelated to the LiteLLM project.
Timeline
- March 19 — Attackers force-pushed malicious commits to 76 of 77 trivy-action version tags and all seven setup-trivy tags, and published a malicious Trivy 0.69.4 release.
- March 24 (10:39 UTC) — Malicious LiteLLM versions 1.82.7 and 1.82.8 were live on PyPI for about 40 minutes.
- March 24 (up to 16:00 UTC) — LiteLLM advised users to treat any install during this window as suspect.
- March 26 — CVE-2026-33634, tracking the ecosystem compromise, was added to CISA's Known Exploited Vulnerabilities catalog.
- July 2 — The FBI issued advisory FLASH-20260702-01, warning that affiliated actors would likely weaponize exfiltrated credentials.
- August 12 — The Hacker News confirmed that neither malicious LiteLLM version appears in PyPI's release history and that the CVE record lists BerriAI LiteLLM 1.82.7 through 1.82.8 as affected.
Technical Analysis
The malicious LiteLLM versions 1.82.7 and 1.82.8 incorporated credential-stealing code. Specifically, version 1.82.8 included a file named `litellm_init.pth`. This `.pth` file is automatically processed by Python at interpreter startup, meaning the malicious code would execute whenever any Python process started in the affected environment, irrespective of whether LiteLLM was explicitly imported or used.
The payload was designed to read various environment variables, including those containing model API keys such as `OPENAI_API_KEY` and `ANTHROPIC_API_KEY`, in addition to collecting SSH keys, cloud credentials, Kubernetes tokens, and database passwords. The collected data was then encrypted and transmitted to `models.litellm[.]cloud`, an attacker-controlled domain.
The malicious LiteLLM releases reached PyPI through the use of an API token that had been exposed as a result of the earlier compromise of the Trivy dependency, which is part of the broader TeamPCP supply-chain campaign. This method of publication bypassed LiteLLM's official CI/CD workflow.
Impact
A dataset obtained by threat intelligence firm CloudSEK, comprising approximately 434,000 captured files, maps potential exposure to more than 2,500 organizations. This figure represents potential exposure based on captured loot and log files, not a confirmed victim count. The credential-stealing code was capable of harvesting cloud keys, SSH keys, Kubernetes tokens, and database passwords.
The FBI warned in a July 2 advisory that credentials exfiltrated during the TeamPCP campaign are likely to be weaponized long after the initial compromise, as long-lived secrets such as static cloud keys, SSH keys, or publishing tokens remain usable unless they have been rotated or revoked.
Confirmed downstream impacts include Checkmarx, which reported that credentials obtained through the Trivy attack enabled unauthorized access to its GitHub repositories and the publication of malicious artifacts. Mercor also stated it was affected by malicious LiteLLM versions and contained unauthorized activity. CERT-EU assessed with high confidence that a European Commission AWS account was compromised through the Trivy supply-chain attack, resulting in the exfiltration of approximately 91.7 GB of compressed data.
Discovery & Response
CloudSEK obtained a dataset of captured files and published it as a public lookup, which is searchable by name or domain and filterable by confidence. LiteLLM identified versions 1.82.7 and 1.82.8 as compromised and advised users to treat any install on March 24 up to 16:00 UTC as suspect. PyPI quarantined the malicious packages approximately 40 minutes after they went live on March 24.
The FBI issued advisory FLASH-20260702-01 on July 2, recommending that organizations rotate CI/CD secrets, publishing tokens, and cloud credentials accessible during the relevant exposure windows. The advisory also suggested moving away from long-lived tokens toward temporary ones. Organizations assessing exposure were advised to check for installations of LiteLLM 1.82.7 or 1.82.8 during the March 24 audit window (10:39 to 16:00 UTC), rotate any secrets those systems could access, and search their GitHub organizations for repositories named `tpcp-docs` or `docs-tpcp`, or those with a `tpcp-docs-` prefix, as the malware created these with a prefix and uploaded stolen data as a release asset.
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.