Cybersecurity & Privacy — 2026-03-24

Trivy Supply Chain Attack Escalates: TeamPCP Backdoors LiteLLM, Deploys CanisterWorm Wiper Targeting Iran

The Trivy supply chain compromise expanded dramatically: TeamPCP pushed malicious versions of LiteLLM (1.82.7-1.82.8) to PyPI containing a three-stage payload that auto-executes on Python startup without import. The payload harvests SSH keys, cloud credentials, Kubernetes secrets, and crypto wallets; deploys privileged pods to every Kubernetes node; and installs a persistent systemd backdoor. Mandiant identified over 1,000 impacted SaaS environments with projections of 10,000 potential victims. Separately, TeamPCP deployed 'CanisterWorm,' a wiper that activates specifically on systems configured with Iran's timezone or Farsi language settings, using blockchain-based ICP canisters to resist takedowns. Suspicious activity resumed March 23, indicating the attacker reestablished access.

Analysis
The CanisterWorm's Iran-targeting wiper component (activating on Farsi locale/Iran timezone) represents a novel convergence of financially motivated cybercrime and conflict-zone targeting. This is the first documented case of a supply chain attack weaponizing timezone-based wipers during an active kinetic conflict.
2 sources
  1. Experts warn of a 'loud and aggressive' extortion wave following Trivy hack - CyberScoop
  2. TeamPCP Backdoors LiteLLM Versions 1.82.7-1.82.8 Likely via Trivy CI/CD Compromise - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE