MIT TRACE

MIT CTL Logo
Back to Main Dashboard

LiteLLM supply-chain compromise distributes malicious PyPI releases

On 24/03/2026, a compromised Trivy dependency used in LiteLLM's CI/CD environment exposed release credentials that attackers used to publish malicious LiteLLM versions 1.82.7 and 1.82.8 through the legitimate PyPI distribution channel. The packages contained credential-stealing code capable of collecting and exfiltrating secrets from downstream systems. LiteLLM reported that the malicious releases were available for about 40 minutes before PyPI quarantined them, and downstream user Mercor later confirmed that it was affected by the LiteLLM supply-chain attack. The incident therefore compromised the integrity of LiteLLM's legitimate software-delivery chain and propagated malicious code to downstream consumers.

80

Estimated severity

80 / 100

96

Source reliability

96 / 100

Approximate Date

24/03/2026

Targeted Company

LITELLM

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

MERCOR (Software vendor)

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseData exfiltrationUse of stolen credentials

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.