Overview
- The malicious LiteLLM releases sat on PyPI for about 40 minutes on March 24 and included a litellm_init.pth file that executed at Python startup to harvest cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets.
- CloudSEK built a public lookup from captured files that it says maps roughly 434,000 pipeline events to more than 2,500 organizations while stressing these figures are reconstructed exposure signals and not proof of successful compromise for every listed entity.
- Investigators say the LiteLLM uploads stem from a wider TeamPCP campaign tied to a compromised Aqua/Trivy scanner token and the incident is tracked as CVE‑2026‑33634 in CISA’s Known Exploited Vulnerabilities catalog.
- Security teams and researchers dispute the precise upload path with explanations ranging from a poisoned build to a direct PyPI upload using exposed publishing tokens, but all accounts agree a leaked credential enabled the chain of events that pushed malicious artifacts to PyPI.
- Authorities including the FBI and CISA and multiple vendors advise treating exposed secrets as compromised, rotating CI/CD and cloud credentials, searching for campaign indicators such as tpcp-docs repositories, and reviewing logs for follow-on activity because stolen credentials can be weaponized long after the initial breach.