Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

LiteLLM Supply Chain Attack Steals 300GB Data and 500K Credentials

SlowMist’s CISO warns crypto developers to urgently check systems, rotate keys, and review logs to prevent losses like Trust Wallet’s breach.

Written By Kenrodgers Fabian
Fact Checked by Dhara Chavda
Published 2026-03-25
Make The Crypto Times preferred on GoogleGoogle
LiteLLM Supply Chain Attack Steals 300GB Data and 500K Credentials

Key Highlights

  • LiteLLM breach exposed 300GB of data and 500K credentials, showing even popular packages can be risky.
  • Malware stole SSH keys, cloud accounts, wallets, and database passwords, spreading via Python and Kubernetes.
  • Developers must remove affected versions, rotate credentials, and check for hidden backdoors immediately.

A serious security breach in LiteLLM has put about 300GB of data and 500,000 user credentials at risk. The problem started when hackers slipped malicious code into PyPI releases 1.82.7 and 1.82.8, allowing anyone who installed them to have sensitive information stolen automatically. 

SlowMist Technology’s Chief Information Security Officer, 23pds, warned cryptocurrency developers to act fast. He posted, “Please immediately verify, rotate relevant keys and credentials as soon as possible, check logs, access records, and any exposure of sensitive data to avoid severe losses similar to the Trust Wallet incident.”

🚨建议所有加密货币开发人员立即自查
有消息称,LiteLLM 漏洞攻击者已盗取约 300GB 数据,并窃取约 50 万个凭证。
请立即核查,尽快轮换相关密钥与凭证,核查日志、访问记录及敏感数据暴露情况,避免出现类似 Trust Wallet 事件的严重损失。 https://t.co/Cm9dHwlbV7

— 23pds (山哥) (@im23pds) March 25, 2026

The attack hit a wide range of sensitive data, including SSH keys, cloud accounts on AWS, GCP, and Azure, Kubernetes setups, Git credentials, environment files, shell histories, encrypted wallets, and database passwords. 

Developer Callum McMahon of FutureSearch discovered the malicious release and reported it to PyPI, while Daniel Hnyk subsequently raised a GitHub issue, bringing it to wider developer attention. The malware could also copy itself, spreading through Kubernetes clusters and leaving behind secret backdoors to maintain access.

How the malware operates

The malware carried out its attack in three main steps. First, it collected sensitive files from the infected computer. Next, it encrypted the stolen data and sent it to a remote server at https://models.litellm.cloud/. Finally, it tried to move laterally within Kubernetes environments, creating new pods that gave it full access to systems. On top of that, a bug in the malware caused a fork bomb, crashing affected machines and revealing the attack.

Commenting on X, Andrej Karpathy highlighted the danger, saying, “Every time you install any dependency you could be pulling in a poisoned package anywhere deep inside its entire dependency tree…The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.”

Immediate steps for developers

Developers need to check if they installed LiteLLM versions 1.82.7 or 1.82.8. If so, they should remove the affected packages, clear any cached files, and look for hidden backdoors like ~/.config/sysmon/sysmon.py. 

All credentials that might have been exposed should be changed immediately. While PyPI has quarantined the malicious package and maintainers are addressing the issue, this attack highlights just how risky supply chain attacks can be in open-source software.

The LiteLLM breach shows that even widely used software packages can carry serious risks. It highlights the need for developers to carefully manage dependencies and stay alert to potential threats.

Also Read: Dark Web, Tor, Crypto Wallets: Indian Police Begins New Cyber Training

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Bitget Withdrawals Resume September 28: Full Schedule After $387.5M Hack
Bitget Withdrawals Resume September 28: Full Schedule After $387.5M Hack
Hand holding a smartphone displaying the Dinari logo in front of a Sei Network wall sign.
Dinari Plans to Bring Tokenized S&P 500 Shares to Sei
Official U.S. Securities and Exchange Commission (SEC) seal mounted on a stone wall.
SEC Staff Clarifies Crypto Investment Contract Rules in New FAQs
Handcuffed individual standing behind physical crypto coins with the flag of Vietnam in the background.
Vietnamese Man Charged Over $16M Crypto Pig Butchering Scam
A row of major cryptocurrency tokens set against a falling red market chart backdrop.
Crypto Stocks ABTC, CRCL, COIN, MSTR Slide as BTC Trades Under $84K

Find Us on Socials

You may also like

CoinMarketCap and Coinglass corporate logos embedded inside transparent glass blocks.

CoinMarketCap Acquires CoinGlass to Bring Derivatives Data to 115M Users

CFTC (Commodity Futures Trading Commission) wall sign mounted in a corporate office setting.

CFTC Charges Cash FX Over $950M Forex Scheme Involving Crypto 

Sui, Ethena, and NEAR Protocol cryptocurrency tokens lined up against a glowing green price chart.

Crypto Sees Broad Weekly Gains as SUI, ENA, NEAR Surge

Hooded figure using a laptop next to a screen displaying the Bitget exchange logo.

Bitget Updates Hack Impact to $387.5M, Offers 5% Recovery Bounty

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information