AI Supply Chain Breach: LiteLLM Compromise on PyPI (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Malicious code injection detected in official PyPI package versions.
- Targets sensitive credentials used for cloud-based AI services.
- Demonstrates evolving threats against the European AI development stack.
"The widely used Python library LiteLLM, which serves as a unified interface for various Large Language Model APIs, was compromised on the PyPI repository. The attack, attributed to the threat group TeamPCP, involved injecting credential-stealing malware designed to exfiltrate sensitive API keys and environment variables from developer environments."
no comments yet.