Build1 publisher3 min readPublished
The agent stack's attack surface is trust: pin the deps, audit the MCP servers
A backdoored LiteLLM build was downloaded about 47,000 times in a three-hour window. Most agent incidents never get a CVE, so your scanner dashboard is not the control you think it is.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A backdoored version of LiteLLM was available on PyPI for about three hours in March.
- The backdoored LiteLLM package was downloaded roughly 47,000 times during that three-hour window.
- LiteLLM is the model gateway underneath CrewAI, DSPy, Microsoft GraphRAG and other agent frameworks.
- There is a decent chance LiteLLM is in a developer's dependency tree without them having run pip install litellm; the author advises checking your lockfile.
- About 47,000 downloads spread over roughly three hours works out to on the order of 15,600 downloads per hour.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
A backdoored version of LiteLLM sat on PyPI for about three hours in March and was pulled roughly 47,000 times in that window, according to a dev.to writeup by nodevguy [1][2]. That matters because almost nobody installs LiteLLM deliberately: it is the model gateway underneath CrewAI, DSPy, Microsoft GraphRAG and a pile of other agent frameworks, so it lands in your lockfile whether or not you ever typed its name [3][4].
Do the arithmetic on the window. Roughly 47,000 downloads across three hours is on the order of 15,600 per hour [5]. There is no human review cadence that catches that if your CI resolves the latest compatible version on every build. Anyone who upgraded during those three hours also pulled in an autonomous attack bot, per the same account [6].
The writeup pulls three more cases from OWASP's State of Agentic AI Security v2.01 [7]. An MCP server called postmark-mcp shipped fifteen clean releases, then added one line of exfiltration code in version sixteen [8]. CVE-2025-6514, rated CVSS 9.6 for remote code execution, landed in core MCP infrastructure used by hundreds of thousands of developers [9]. And CVE-2026-22708 against Cursor let an attacker poison the agent's execution environment so that allowlisted commands such as git branch delivered arbitrary payloads, which means the allowlist became the delivery path because allowlisted commands were auto-approved [10]. Separately, Lakera's research found that indirect prompt injection through poisoned data sources can corrupt an agent's long-term memory, leaving it with persistent false beliefs that it defends when a human pushes back [11].
None of that is a bug you wrote. It arrives through a package, a tool config, or a data source your framework already trusts.
The number that should reorder your backlog: in OWASP's Q1 2026 exploit roundup, eight major AI incidents were documented between January and mid-April, and exactly one received a CVE [12]. That is 12.5 percent coverage [13]. The other seven traced to misconfiguration, excessive agency, supply chain failure, or prompt injection [14], and Dependabot, Snyk and npm audit are all built around the CVE pipeline [15]. Keep them. Stop reading a green dashboard as a statement about your agent setup.
Three controls are cheap enough to land this week. Pin agent dependencies to explicit versions and adopt new releases on a delay, for example seven days after publish with a changelog read, which is a real control against exactly the three-hour LiteLLM window [16]. Treat every MCP server as arbitrary code with your agent's access: check who publishes it, whether the repo has real history rather than fifteen suspiciously tidy releases, what it does on the wire when you proxy it once, and whether it needs network egress at all, because most tool servers do not [17]. Then scope credentials per task rather than per agent, using short-lived tokens, read-only by default, and separate credentials per tool so one hijacked server does not unlock the rest [18]. The writeup reports that 61 percent of agent security incidents in 2026 data traced back to over-permissioned credentials [19].
What to watch: whether the next OWASP roundup narrows the gap between total agentic incidents and CVE-tracked ones, since that ratio determines how much of your risk your existing tooling can even see [12][15]. Watch, too, for the version-sixteen pattern in MCP registries, where install base is built on clean releases before the payload ships [8]. In the meantime, grep your own lockfile for litellm and see what you find [4].