Trojanized LiteLLM Package Executed Multi-Stage Supply-Chain Attack

On March 24, 2026 SentinelOne's Singularity Platform autonomously detected and stopped a trojaned LiteLLM Python package executing malicious Python across multiple customer environments. The compromised package, uploaded hours earlier, ran payloads that attempted data theft, persistence, Kubernetes lateral movement, and encrypted exfiltration. SentinelOne says the platform contained the attack the same day with no human queries, no SOC triage, and no signature updates — showing LLM proxy packages can be weaponized to outpace manual defenses.

Part of the PlainSec briefing for 2026-04-01

Sources