LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts
Brief
A supply chain compromise involving LiteLLM highlights how a short-lived malicious package can create long-term risks across cloud environments, CI/CD systems, source-code repositories, Kubernetes clusters, package registries, and AI services.
CloudSEK said the March 2026 campaign was linked to Team PCP and involved compromised releases of LiteLLM versions 1.
- 7 and 1.
- 8 on PyPI.
The packages were reportedly available for around 40 minutes, but the impact window may be much longer because stolen credentials can remain valid after a malicious package is removed.
The company’s reconstructed exposure dataset includes more than 2,500 organizations and approximately 434,000 potentially exposed CI/CD pipelines.
However, inclusion in the dataset should not be treated as proof of compromise.
