Forcepoint details TeamPCP supply chain attack that turned LiteLLM into a credential stealer
A supply chain attack just weaponized LiteLLM—a library used by 100+ LLM providers. Your AI stack could be next.

Why it matters
Supply chain security is becoming a critical vulnerability in the AI economy. As enterprises integrate open-source LLM gateways into production, attackers are targeting the connective tissue of AI infrastructure—not the models themselves.
The key facts
7 to knowLiteLLM compromised via supply chain attack by TeamPCP
LiteLLM serves as unified gateway to 100+ LLM providers
Attack turned library into credential-stealing tool targeting cloud/AI infrastructure
Two malicious releases deployed
Research published by Forcepoint X-Labs
Attack vectors: open-source dependency chains, LLM infrastructure
Published May 18, 2026
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: A new report out today from cybersecurity company Forcepoint LLC’s X-Labs research team details a supply chain attack that compromised LiteLLM, a widely used open-source Python library that serves as a unified gateway to more than 100 large language model providers, turning two malicious releases…