Last seen March 26, 2026

AI Security Incident

Evidence indicates that the affected technology is affected by a security issue.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that the affected technology is affected by a security issue.

Why This Matters

Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Mar 26, 2026 05:30

Last Seen

Mar 26, 2026 05:30

Exploitation status: UNKNOWN

Primary entities:

Credential Exposure Remote Code Execution Supply Chain

Timeline

  • Incident first seen
    Mar 26, 2026 05:30

    BugSkan first recorded this incident.

  • Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise - www.trendmicro.com
    Mar 26, 2026 05:30

    trendaisecurity.com · Malware

Sources

Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise - www.trendmicro.com

trendaisecurity.com · Mar 26, 2026 05:30

TeamPCP orchestrated a sophisticated supply chain attack, compromising the Trivy security scanner's CI/CD pipeline to publish malicious versions of the LiteLLM AI proxy package to PyPI. These trojanized versions deployed a multi-stage payload for credential harvesting, Kubernetes lateral movement, and persistent remote code execution.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence