LiteLLM Supply Chain Attack Exposes 500,000 Credentials, Puts Crypto Wallet Seeds at Risk

LiteLLM Supply Chain Attack Exposes 500,000 Credentials, Puts Crypto Wallet Seeds at Risk

N
News Editor 01
2026-07-23 23:25:16
A supply chain attack on LiteLLM led to malicious code being published in versions 1.82.7 and 1.82.8. Reports say the operation exposed hundreds of GB of data and 500,000 credentials, including cloud access keys and crypto wallet seed phrases.
LiteLLMsupply-chain-attackcredential-leakcrypto-walletcybersecurity

LiteLLM has been hit by a supply chain attack, with malicious code published in versions 1.82.7 and 1.82.8. The source material says the open-source AI package, downloaded 3.4 million times per day, was tied to a breach involving hundreds of GB of data and 500,000 credentials. That puts software pipelines, cloud infrastructure, and crypto wallet security in the same blast radius.

The breach began upstream with Trivy

The incident was described as a nested supply chain attack rather than an isolated compromise. Analysis cited from Snyk and Kaspersky traces the setup back to late February 2026. Attackers reportedly abused a GitHub CI/CD weakness to steal access tokens from maintainers of Trivy, the open-source security scanner used by many organizations to check systems for vulnerabilities.

From there, the attackers used a similar method to seize LiteLLM’s publishing permissions on March 24. They then uploaded the tainted releases. Because LiteLLM sits between developers and multiple large language models, a compromise at this point can move downstream through dependency chains very quickly. One package was enough.

Three-stage payload targeted cloud keys and wallet seed phrases

According to Snyk’s breakdown, the malicious code operated in three stages. First, it harvested sensitive data from infected machines, including SSH keys, cloud credentials for services such as AWS and GCP, and seed phrases for cryptocurrency wallets holding assets like Bitcoin and Ethereum. For crypto users and teams, that detail matters. A leaked seed phrase is not a routine secret rotation problem.

Second, the collected data was encrypted, bundled, and sent to attacker-controlled spoofed domains. Third, the malware planted a backdoor inside the system. If it detected a Kubernetes environment, it attempted to spread across all nodes in the cluster. That turns a single infected workstation or build system into a much larger infrastructure event.

A bug in the malware helped expose the operation

The campaign came to light after developer Callum McMahon tested an extension for the Cursor editor. As described in the source, AI-assisted debugging led him to a flaw in the malicious code that accidentally triggered a Fork Bomb, causing the process to replicate itself and exhaust system memory and compute resources. The mistake made the intrusion visible earlier than the attackers likely intended.

What affected users are being told to check

The source does not provide a full command-by-command remediation guide, but it is clear about the first priorities: determine the scope of exposure and remove any backdoor access. For teams that installed or called the affected versions, the key checks include LiteLLM version history, GitHub Actions and CI/CD configurations, unexpected outbound connections, suspicious credential usage, and signs of persistence on hosts.

Kaspersky also recommended several open-source tools to harden GitHub Actions security. These include tools for static analysis and GitHub Actions misconfiguration detection, tools for identifying structural weaknesses in automation pipelines, and an OpenSSF-built GitHub application that can enforce security policies across organizations and repositories. The source material did not list the tool names.

Researchers linked the activity to TeamPCP

Based on analysis cited from Snyk and security-focused engineer Huli, the group behind the attack was identified as TeamPCP. The report says the group has been active since December 2025 and has used channels on platforms such as Telegram. It also notes that the name appears to echo the recent OpenClaw trend in AI circles.

The article places the LiteLLM case alongside other software supply chain incidents, including compromised NPM accounts that led to malicious JavaScript packages and a case disclosed by Anthropic involving AI-assisted cyber espionage. The pattern is plain: as AI tooling becomes common in development workflows, permission control and supply chain security are no longer secondary concerns. For teams holding cloud credentials, private keys, or wallet seed phrases, the risk sits inside core infrastructure.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.