Skip to main content
← All Articles

Tag

#LiteLLM

14 articles

Advertisement

MEDIUM
Supply Chain

TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks

Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.

Runtime Rebel Intel
3 min read · Sep 1, 2026
CRITICAL
Supply Chain

TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs

A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security's Trivy scanner, not LiteLLM.

Runtime Rebel Intel
5 min read · Aug 15, 2026
Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP
CRITICAL
Supply Chain

Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP

Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.

Runtime Rebel Intel
4 min read · Aug 12, 2026
LiteLLM Proxy Server Takeover via Critical Vulnerability Chain
HIGH
Vulnerabilities

LiteLLM Proxy Server Takeover via Critical Vulnerability Chain

Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.

Runtime Rebel Intel
3 min read · Jun 15, 2026
CVE-2026-42271: BerriAI LiteLLM RCE Exploited in the Wild
CRITICAL
Vulnerabilities

CVE-2026-42271: BerriAI LiteLLM RCE Exploited in the Wild

CISA warns of active exploitation of CVE-2026-42271 in BerriAI LiteLLM. This command injection flaw allows attackers to achieve RCE and compromise AI proxies.

Runtime Rebel Intel
3 min read · Jun 9, 2026
CRITICAL
Vulnerabilities

LiteLLM Proxy Data Exposure & Modification — Urgent Patch Required

Critical vulnerability in LiteLLM proxy enables unauthorized database read/modify access. Exploitation observed shortly after disclosure. Patch immediately.

Runtime Rebel Intel
4 min read · Apr 29, 2026

Advertisement

CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection
CRITICAL
Vulnerabilities

CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection

Attackers are actively exploiting CVE-2026-42208, a critical SQL injection flaw in LiteLLM, within 36 hours of disclosure. Patch to prevent database compromise.

Runtime Rebel Intel
4 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

CVE-2026-42208: LiteLLM Pre-Auth SQLi Actively Exploited – Patch Now

Hackers are actively exploiting CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in LiteLLM, to access sensitive data.

Runtime Rebel Intel
5 min read · Apr 29, 2026
HIGH
Supply Chain

litellm 1.82.8 Supply Chain Compromise via Malicious .pth File

Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Supply Chain

Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft

AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx Wider Scope & LiteLLM PyPI Compromise

An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.

Runtime Rebel Intel
5 min read · Mar 26, 2026
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
HIGH
Supply Chain

Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack

TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.

Runtime Rebel Intel
5 min read · Mar 25, 2026
HIGH
Supply Chain

LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials

TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.

Runtime Rebel Intel
5 min read · Mar 25, 2026
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
HIGH
Supply Chain

TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise

TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.

Runtime Rebel Intel
3 min read · Mar 24, 2026