LiteLLM PyPI backdoored as TeamPCP cascade reaches Python
TeamPCP used credentials harvested from the Trivy compromise to publish trojanised litellm 1.82.7 and 1.82.8 to PyPI on 24 March 2026 (~10:39 and 10:52 UTC). Malicious wheels drop a litellm_init.pth file in site-packages, executing a credential stealer at every Python interpreter start. PyPI quarantined the packages ~40 minutes after publication. Attackers later claimed ~500,000 credentials from this single compromise. LiteLLM averages ~3M daily downloads and ships in ~36% of cloud environments.
Versions named here: 1.82.7, 1.82.8