Supply-Chain Malware in LiteLLM Harvests Cloud Credentials

A malicious PyPI dependency in the open-source LiteLLM project installed credential-harvesting malware that collected environment variables, SSH keys and passwords. LiteLLM is widely adopted—Snyk reports up to 3.4 million downloads per day—so stolen credentials could expose cloud keys, API tokens and downstream packages. Investigators traced the publishes to a compromised maintainer account used in LiteLLM's pipeline and flagged a possible link to an earlier Trivy compromise.

Part of the PlainSec briefing for 2026-03-27

Sources