Trivy Supply Chain Attack Escalates: TeamPCP Backdoors LiteLLM, Deploys CanisterWorm Wiper Targeting Iran
The Trivy supply chain compromise expanded dramatically: TeamPCP pushed malicious versions of LiteLLM (1.82.7-1.82.8) to PyPI containing a three-stage payload that auto-executes on Python startup without import. The payload harvests SSH keys, cloud credentials, Kubernetes secrets, and crypto wallets; deploys privileged pods to every Kubernetes node; and installs a persistent systemd backdoor. Mandiant identified over 1,000 impacted SaaS environments with projections of 10,000 potential victims. Separately, TeamPCP deployed 'CanisterWorm,' a wiper that activates specifically on systems configured with Iran's timezone or Farsi language settings, using blockchain-based ICP canisters to resist takedowns. Suspicious activity resumed March 23, indicating the attacker reestablished access.
The CanisterWorm's Iran-targeting wiper component (activating on Farsi locale/Iran timezone) represents a novel convergence of financially motivated cybercrime and conflict-zone targeting. This is the first documented case of a supply chain attack weaponizing timezone-based wipers during an active kinetic conflict.