1
Published signals
currently linked to this company
Company intelligence
pypi.org
This company page brings together public reporting currently associated with Pypi. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
1
confidence classifications
July 2, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Pypi. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
On March 27, 2026, malicious versions (1.82.7 and 1.82.8) of the LiteLLM library were published on PyPI for approximately 40 minutes as part of a supply-chain attack. These compromised versions were designed to exfiltrate credentials from any system that installed them, affecting a significant percentage of cloud environments.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Pypi.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.