TeamPCP Backdoors LiteLLM Python Package via Trivy CI/CD Compromise; 36% of Cloud Environments Exposed
TeamPCP, the threat actor behind the Trivy and KICS compromises, backdoored litellm versions 1.82.7 and 1.82.8 on PyPI through the package's use of Trivy in its CI/CD pipeline. The three-stage payload includes a credential harvester sweeping SSH keys, cloud credentials, Kubernetes secrets, and cryptocurrency wallets; a Kubernetes lateral movement toolkit deploying privileged pods to every node; and a persistent systemd backdoor polling for additional binaries. LiteLLM is present in 36% of all cloud environments and is downloaded approximately 3.4 million times daily. Wiz reported that TeamPCP appears to be collaborating with LAPSUS$, representing an ecosystem-wide cascade targeting the modern cloud-native and AI stack. Both malicious versions have been removed from PyPI.
1 sources
- Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens -
BleepingComputer