Suspicious Python Startup .pth File Creation for Interpreter Persistence

PremiumReviewedSigma · Medium · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-08-23
Updated
2026-08-28

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of the litellm_init.pth Python path-configuration file. The LiteLLM supply-chain attack abused a .pth file that Python auto-executes at interpreter startup to run attacker code whenever the environment is used as documented by Kaspersky. A malicious .pth dropped into a site-packages directory grants stealthy persistence tied to every Python invocation.

Related detections9 linkedT1059.006 — drag to rearrange
Malicious TeamPCP LiteLLM .pth Startup Hook and Payload Dropper (via file_event)
Suspicious Kimsuky Python Backdoor Staging in Winii Directory (via file_event)
SynkLoader Python Stager Execution from AppData via pythonw (via process_creation)
Malicious TeamPCP systemd User Unit Dropper via sysmon.py Persistence (via file_event)
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Malicious Backdoored liblzma XZ Utils Library File via file_event
AteraAgent malicious installations
Suspicious SSH Daemon Spawning Shell via xz Backdoor (via process_creation)
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Suspicious Python Startup .pth File Creation for Interpreter Persistence
Pivot detection · T1059.006 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.