Malicious LiteLLM versions linked to TeamPCP supply chain attack
ID: 75ccd87b-b8a9-5e0f-8529-b9eb199d9d3d
STIX ID: report--75ccd87b-b8a9-5e0f-8529-b9eb199d9d3d
Feed Name: Security Affairs
Endor Labs discovered that LiteLLM PyPI releases 1.82.7 and 1.82.8 were backdoored—likely via a Trivy CI/CD compromise—embedding obfuscated base64 payloads that run at import (and via a .pth on 1.82.8) to harvest SSH keys, cloud credentials, Kubernetes secrets, wallets and .env files, propagate across Kubernetes via privileged pods, and install a persistent systemd backdoor; the activity is attributed with high confidence to TeamPCP and ties to a broader multi-ecosystem supply-chain campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
