Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)

Identifies Linux process executions matching indicators tied to backdoored LiteLLM v1.82.7/v1.82.8 credential-stealer and persistence activity.

FreeReviewedSigma · High · v5
Product
linux
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-03-30
Updated
2026-07-31

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Linux process execution patterns consistent with activity associated with backdoored LiteLLM package versions v1.82.7 and v1.82.8. It looks for command lines that decode and execute suspicious embedded Python content, download a specific tarball from a configured LiteLLM models endpoint, and launch payload artifacts consistent with credential collection and persistence setup. The detection relies on process creation telemetry including Image paths, full CommandLine arguments, and parent process context.

Related detections9 linkedT1195.002 — drag to rearrange
Linux Persistence File Creation Targeting sysmon.py and systemd user service
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious Archiving of Registry Hives via WinRAR (UAT-8099)
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious Koske Persistence via Systemd Service and Shell Profile Hijack (via process_creation)
Suspicious Linux CoinMiner Watchdog Staging in Shared Memory (via process_creation)
Suspicious systemd Service Persistence Creation (via process_creation)
Suspicious Data Staging via Password-Protected Archive Utility (via process_creation)
Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)
Pivot detection · T1195.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.