08/18/2026

LiteLLM in the crosshairs: Supply Chain Attack on AI Infrastructure

Supply Chain Attack on AI Infrastructure Awareness

This article was translated from German with the help of AI technologies. 

LiteLLM is an environment that allows users to bundle different AI platforms and configure them through a single interface. An attacker group called “TeamPCP” managed to compromise LiteLLM. However, this did not happen directly, but via an automated security scanner whose updates were used to inject malicious code into LiteLLM. The infected packages were available on the Python Package Index (PyPI) for only around 40 minutes before they were discovered — but during that time, hundreds of thousands of systems may have downloaded them.

Cases like this directly target the CI/CD (Continuous Integration/Continuous Delivery) environment of a software supply chain in which LiteLLM is used. With the stolen API keys, tokens and credentials, attackers were able to inject additional malicious code into hundreds of thousands of environments and potentially also gain access to data processed by a connected LLM.

 

What to do next

The first measure for affected companies should be to change passwords and revoke tokens and keys if they were processed at any point via LiteLLM or an LLM connected to it.

The actual risk is, on the one hand, that stolen credentials may only be used after a delay. On the other hand, this incident also brings back memories of the case in which Anthropic’s AI independently launched an attack on companies and, for this purpose, also placed a prepared software package — in this case on PyPI. It remained there for less than an hour, but that was still enough to infect 15 systems.

The incident described here already took place in March 2026. Exactly which companies were affected has only now become known through a report by CloudSEK.

The affected LiteLLM versions are 1.82.7 and 1.82.8. The current version of LiteLLM at the time of this writing is 1.97.0.