criticalOther UnknownPublish anonymously
LiteLLM PyPI supply chain backdoor — TeamPCP campaign compromises 3.4M daily downloads
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
TeamPCP compromised LiteLLM (3.4M daily downloads) via a poisoned Trivy GitHub Action that stole the PYPI_PUBLISH token. Backdoored versions contained a three-stage credential harvester collecting SSH keys, cloud tokens, Kubernetes configs. Available ~3 hours before PyPI quarantine.