
LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts
A supply chain compromise involving LiteLLM highlights how a short-lived malicious package can create long-term risks across cloud environments, CI/CD systems, source-code repositories, Kubernetes clusters, package registries, and AI services. CloudSEK said the March 2026 campaign was linked to Team PCP and involved compromised releases of LiteLLM versions 1.82.7 and 1.82.8 on PyPI. The packages […]
The post LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts appeared first on Cyber Security News.