LiteLLM AI gateway releases on PyPI backdoored to steal credentials
Attackers used publishing credentials stolen through an earlier Trivy compromise to push malicious LiteLLM releases to PyPI for about 40 minutes. The payload harvested cloud, Kubernetes, CI/CD and database secrets and installed a backdoor. Analysts later assessed credentials from 2,500+ organizations were exposed, and AI recruiter Mercor confirmed it was affected.
- Disclosed
- 24 Mar 2026
- Organization
- Multiple
- Vendor
- Any model
- Product
- LiteLLM (open source)
- Kind of AI
- Model or package
- AI's role
- Poisoned supply chain
- How it happened
- Supply chain and access: Poisoned package
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- Ecosystem-wide
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2026-33634