Malicious versions of the LiteLLM Python package were briefly available on PyPI, exposing AI software supply chain risks. Attackers aimed to harvest sensitive credentials and cloud access through compromised dependencies.