Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign
wiz.io | blog | #cloud | #supply-chain | #malware | #credential-theft | #pypi | #litellm | #persistence | #teampcp
Summary
TeamPCP trojanized LiteLLM with malicious PyPI versions 1.82.7 and 1.82.8: the payloads abuse Python's .pth mechanism to run base64 payloads at startup, exfiltrating cloud and CI/CD credentials.
- Published
- Collected
Skip to content