litellm (2)

31224320696?profile=RESIZE_400xA cybersecurity analysis by CloudSEK revealed the scale of the March 2026 LiteLLM supply-chain attack, which exposed about 434,000 CI/CD pipelines at more than 2,500 companies worldwide.  Continuous Integration (CI) and Continuous Delivery (CD) pipelines are automated workflows that build, test, and deploy software from a developer’s environment to production users.  Although the malicious packages were active for only about 40 minutes, the breach may have exposed critical credentials and securi

31111049692?profile=RESIZE_400xOn 24 March 2026, two versions of the litellm Python package on PyPI were found to contain malicious code.  The packages (versions 1.82.7 and 1.82.8) were published by a threat actor known as TeamPCP after they obtained the maintainer's PyPI credentials through a prior compromise of Trivy, an open source security scanner used in litellm's CI/CD pipeline.

The malicious versions were available for approximately three hours before PyPI quarantined the package. litellm is downloaded roughly 3.4 mill