Sev0AI security incidents, tracked

All incidents / Supply chain and access

LiteLLM AI gateway releases on PyPI backdoored to steal credentials

Multiple, disclosed 24 Mar 2026. Supply chain and access Data exposed High

Attackers used publishing credentials stolen through an earlier Trivy compromise to push malicious LiteLLM releases to PyPI for about 40 minutes. The payload harvested cloud, Kubernetes, CI/CD and database secrets and installed a backdoor. Analysts later assessed credentials from 2,500+ organizations were exposed, and AI recruiter Mercor confirmed it was affected.

Disclosed
24 Mar 2026
Organization
Multiple
Vendor
Any model
Product
LiteLLM (open source)
Kind of AI
Model or package
AI's role
Poisoned supply chain
How it happened
Supply chain and access: Poisoned package
Harm
Data exposed
Data involved
Credentials
Reach
Ecosystem-wide
Severity
High
Model at fault
No
Status
Confirmed
Vulnerability IDs
CVE-2026-33634

Sources

  1. https://docs.litellm.ai/blog/security-update-march-2026
  2. https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/
  3. https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "LiteLLM AI gateway releases on PyPI backdoored to steal credentials", https://sev0.fyi/incidents/2026-03-24-litellm-pypi-supply-chain/