TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise
ID: 897cd636-1585-5aca-b73d-e1e78a2c990c
STIX ID: report--897cd636-1585-5aca-b73d-e1e78a2c990c
Feed Name: Infosecurity Magazine (News)
A compromised LiteLLM PyPI package (versions 1.82.7 and 1.82.8) distributed credential‑stealing malware that executed on import or on Python process start, exfiltrated SSH keys, cloud and database credentials, Kubernetes secrets, and other sensitive artifacts, and attempted lateral movement and persistence via system service backdoors; researchers link the incident to the TeamPCP supply‑chain campaign and warn downstream users to rotate secrets and hunt for intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
