PULSE NAME
Malicious PyPI Package - LiteLLM Supply Chain Compromise
WHITE TeamPCP AlienVault 2026-03-25 Modified: 2026-03-25
3
IOCs
LOW VOLUME
A malicious supply chain attack has been discovered in the Python Package Index package litellm version 1.82.8. The compromised package contains a malicious .pth file that executes automatically when the Python interpreter starts, without requiring explicit import. This file, located in site-packages/, exfiltrates sensitive information including environment variables, SSH keys, and cloud credentials to an attacker-controlled server. The payload is double base64-encoded to evade basic static analysis. PyPI administrators have quarantined the project to limit its spread. Users are advised to check for the malicious file, rotate all potentially exposed credentials, and audit their PyPI publishing process. The attack is attributed to TeamPCP and is actively exploited in the wild.
Indicators of Compromise (3)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://checkmarx.zone/raw 2026-03-25
domain checkmarx.zone 2026-03-25
hostname models.litellm.cloud 2026-03-25