Tag: TeamPCP Backdoors

TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
News

TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise

The popular Python program litellm has been hacked by TeamPCP, the threat actor responsible for the recent breaches of Trivy and KICS. Two malicious versions of the software feature a credential harvester, a toolkit for Kubernetes lateral movement, and a persistent backdoor. Litellm versions 1.82.7 and 1.82.8 were released on March 24, 2026, according to several security vendors, including Endor Labs and JFrog. This was probably caused by the package's use of Trivy in their CI/CD workflow. Since then, PyPI has eliminated both of the backdoored versions. According to Endor Labs researcher Kiran Raj, the attack consists of three stages: a credential harvester that scans SSH keys, cloud credentials, Kubernetes secrets, cryptocurrency wallets, and.env files; a Kubernetes lateral movemen...