The Package Registry Layer: How Supply-Chain Attacks Are Targeting Agent Infrastructure
The LiteLLM Breach and the New Reality of AI Infrastructure On March 24, 2026, the Python Package Index (PyPI) hosted malicious versions of the LiteLLM library—specifically 1.82.7 and 1.82.8—for approximately 40 minutes. Orchestrated by the threat actor Team PCP, this incident represents a structural shift in how we must evaluate the integrity of the tools…