logo

LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks

ID: d41d8e6e-d1c7-5ea2-a7d2-1f7f272be7c0

STIX ID: report--d41d8e6e-d1c7-5ea2-a7d2-1f7f272be7c0

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

TeamPCP, a cybercriminal group, conducted a series of supply‑chain attacks compromising open‑source packages (including LiteLLM on PyPI) and associated GitHub workflows to deliver credential stealers, malware droppers, a Python backdoor, and a worm; affected parties are advised to remove malicious packages, rotate exposed credentials, and investigate for persistence and additional payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.