tech π¨ Malicious LiteLLM releases potentially hit 2,100+ orgs
Malicious LiteLLM releases, containing credential-stealing code, were present on PyPI for about 40 minutes in March. Threat intelligence firm CloudSEK mapped potential exposure to over 2,500 organizations, based on 434,000 captured files. The compromised versions, 1.82.7 and 1.82.8, were live on March 24 before being quarantined. This incident is part of a wider TeamPCP supply-chain campaign linked to Trivy. Affected parties are advised to immediately rotate all long-lived credentials instead of waiting for proof. π¬