logo

TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise

ID: 897cd636-1585-5aca-b73d-e1e78a2c990c

STIX ID: report--897cd636-1585-5aca-b73d-e1e78a2c990c

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

...
...

A compromised LiteLLM PyPI package (versions 1.82.7 and 1.82.8) distributed credential‑stealing malware that executed on import or on Python process start, exfiltrated SSH keys, cloud and database credentials, Kubernetes secrets, and other sensitive artifacts, and attempted lateral movement and persistence via system service backdoors; researchers link the incident to the TeamPCP supply‑chain campaign and warn downstream users to rotate secrets and hunt for intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.