logo

33K Exposed LiteLLM Deployments and the C2 Servers Behind TeamPCP's Supply Chain Attack

ID: 2c7581ca-a9a7-5251-b9dd-a4044b0865a4

STIX ID: report--2c7581ca-a9a7-5251-b9dd-a4044b0865a4

Feed Name: Hunt.io Blog

Threat Score
88/100

Date Published: 2026-03-28

Date Updated: 2026-04-28

...
...

TeamPCP published trojanized LiteLLM packages to PyPI that silently install a multi-stage infostealer and RAT: it harvests SSH and cloud credentials (including AWS IMDSv2), encrypts and exfiltrates data to models.litellm.cloud, and can escalate from a single pod to full Kubernetes cluster takeover; persistent implants poll checkmarx.zone for payloads and use two C2 frameworks (AdaptixC2 and Havoc), with 33,688 internet-facing LiteLLM instances observed and detailed IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.