TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise
ID: 7278c815-223a-52d9-9c99-4504a32e8b0f
STIX ID: report--7278c815-223a-52d9-9c99-4504a32e8b0f
Feed Name: The Hacker News
TeamPCP compromised the Python package litellm (versions 1.82.7 and 1.82.8) by injecting malicious code into the package wheel and adding a .pth startup launcher, resulting in a three-stage attack that harvests credentials (SSH keys, cloud credentials, K8s secrets, wallets and .env files), deploys privileged pods for Kubernetes lateral movement and chroots to install a persistent systemd backdoor that polls a remote URL for follow-on payloads; exfiltration is performed to models.litellm.cloud and the campaign is tied to prior compromises of Trivy and other developer-supply-chain ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
