---
title: "LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8"
description: "Malicious LiteLLM releases 1.82.7 and 1.82.8 shipped a .pth file that ran on every Python startup to harvest credentials. What to check on your fleet."
url: "https://anomity.ai/blog/litellm-supply-chain-malicious-pypi-1-82-8/"
source: html
---

On this page

- What happened
- Why this is an agentic-endpoint risk
- How Anomity surfaces and governs it
- What to check across your fleet
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8

![Anomity robot illustrating LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8]

Advisory High

# LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8

Anomity Research
Anomity Threat Research
·
Mar 24, 2026
·
2 min read

Share: Copied

AI Supply-Chain Attacks · High · PyPI: litellm 1.82.7 / 1.82.8 · Mar 24, 2026

Affected litellm 1.82.7 and 1.82.8 (PyPI; quarantined)

## What happened

Malicious versions of the **LiteLLM** Python package - **1.82.7 and 1.82.8** - were published to PyPI carrying a weaponized `.pth` file that executes automatically on Python interpreter startup. LiteLLM is a widely used LLM gateway/proxy, so the blast radius spans developer machines, CI/CD pipelines, and production workloads. The payload enabled large-scale credential harvesting and exfiltration, with reported follow-on lateral movement. PyPI quarantined the malicious releases, but any environment that installed them in the window should be treated as compromised.

## Why this is an agentic-endpoint risk

LLM gateways sit at the center of agent traffic and hold the keys to everything an agent can reach. A `.pth` hook that runs on every Python startup is the supply-chain equivalent of a [blanket permission grant](https://anomity.ai/blog/ai-agents-are-the-new-shadow-it/): silent, automatic, and credential-hungry. It is also invisible to controls that watch the wire rather than the endpoint - the compromise is a local package, executing locally, before any network policy applies.

## How Anomity surfaces and governs it

Anomity inventories AI gateways and the tooling around your agents across every managed endpoint and surfaces the installed version, so finding every host that pulled `litellm 1.82.7` or `1.82.8` is one query, not an incident-response sweep. Install and version-change events are recorded in the [90-day audit trail](https://anomity.ai/#outcomes), giving you a precise window of exposure. On agents that expose a hook, [runtime governance](https://anomity.ai/#runtime-governance) can deny the outbound tool calls a credential-stealer would attempt - and because Anomity collects metadata only, secret values never leave the endpoint.

## What to check across your fleet

- Search every endpoint, CI runner, and image for litellm at 1.82.7 or 1.82.8 ; pin to a known-good version.
- Rotate any credentials reachable from affected environments - SSH keys, cloud tokens, Kubernetes configs, and LLM API keys.
- Review the audit trail for the install window to scope exposure precisely.
- Add a policy gate: AI gateway packages must be pinned and verified before install.
- Watch for unexpected outbound connections from Python processes at startup.

For the broader pattern, see our work on [AI supply-chain attacks](https://anomity.ai/blog/#advisory). To see your own gateway and agent posture, [book a 30-minute demo](https://anomity.ai/#early-access).

Share: Copied

## Frequently asked questions

Which LiteLLM versions were malicious?
PyPI releases 1.82.7 and 1.82.8 were trojanized with a weaponized .pth file that executed automatically whenever the Python interpreter started. The malicious versions were quarantined by PyPI, but any environment that installed them during the window should be treated as compromised and have its credentials rotated.

What did the payload do?
The .pth startup hook enabled large-scale credential harvesting - sweeping SSH keys, cloud credentials, Kubernetes configs, and LLM API keys - and exfiltrating them, with reported follow-on lateral movement. Because it ran at interpreter startup, it executed across local environments, CI/CD, and production workloads.

How does Anomity help against AI supply-chain attacks like this?
Anomity inventories AI gateways, agents, and the tooling around them across managed endpoints and surfaces the installed versions, so identifying every host that pulled a known-bad release is a single query. It records install and change events in a 90-day audit trail, and on agents that expose a hook it can deny the tool calls a credential-stealing payload would attempt.

## Related

[Advisory High ### Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents Plugin4Shell let a plugin owner swap reviewed code under an intact SHA pin. Auto-update made it zero-click. Two agents patched, two never will. Anomity Research · Oct 2, 2026 · Plugin4Shell (AIR, 2026-09-17); no CVE assigned](https://anomity.ai/blog/plugin4shell-coding-agent-plugin-sha-pinning-bypass/)

[Advisory High ### OpenClaw 2.0: What the Biggest Rewrite Yet Changes for Skill Supply-Chain Risk OpenClaw 2.0 landed on 30 August 2026 as the project's largest rewrite. Unit 42 and Backslash research shows the skill supply chain it inherits is still delivering malware - and our own scans separate the official skills from the ecosystem around them. Anomity Research · Sep 2, 2026 · No CVE. OpenClaw 2.0 (release notes 2026.8.1), 30 August 2026; Unit 42 skill analysis (February-May 2026); Backslash Security risk review (4 June 2026)](https://anomity.ai/blog/openclaw-2-0-security-skill-supply-chain/)

[Advisory High ### MCPJacking: How Expired Domains Take Over Registry MCP Servers MCPJacking hijacks listed MCP servers by reclaiming their expired domains. AIR Security reports 155 hijackable entries in the official MCP registry. Anomity Research · Aug 29, 2026 · MCPJacking (AIR Security, August 2026; no CVE published)](https://anomity.ai/blog/mcpjacking-expired-domain-mcp-registry-hijack/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8",
  "description": "Malicious LiteLLM releases 1.82.7 and 1.82.8 shipped a .pth file that ran on every Python startup to harvest credentials. What to check on your fleet.",
  "datePublished": "2026-03-24",
  "dateModified": "2026-03-24",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/litellm-supply-chain-malicious-pypi-1-82-8/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/skills-supply-chain.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "AI Supply-Chain Attacks",
  "url": "https://anomity.ai/blog/litellm-supply-chain-malicious-pypi-1-82-8/",
  "keywords": "LiteLLM supply chain attack PyPI, PyPI: litellm 1.82.7 / 1.82.8, supply chain, LiteLLM, PyPI, credential theft, LLM gateway"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Which LiteLLM versions were malicious?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "PyPI releases 1.82.7 and 1.82.8 were trojanized with a weaponized .pth file that executed automatically whenever the Python interpreter started. The malicious versions were quarantined by PyPI, but any environment that installed them during the window should be treated as compromised and have its credentials rotated."
      }
    },
    {
      "@type": "Question",
      "name": "What did the payload do?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The .pth startup hook enabled large-scale credential harvesting - sweeping SSH keys, cloud credentials, Kubernetes configs, and LLM API keys - and exfiltrating them, with reported follow-on lateral movement. Because it ran at interpreter startup, it executed across local environments, CI/CD, and production workloads."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help against AI supply-chain attacks like this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity inventories AI gateways, agents, and the tooling around them across managed endpoints and surfaces the installed versions, so identifying every host that pulled a known-bad release is a single query. It records install and change events in a 90-day audit trail, and on agents that expose a hook it can deny the tool calls a credential-stealing payload would attempt."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "LiteLLM Supply-Chain Compromise - Malicious PyPI Release 1.82.8",
      "item": "https://anomity.ai/blog/litellm-supply-chain-malicious-pypi-1-82-8/"
    }
  ]
}
```
