Cybersecurity & Privacy — 2026-03-25
TeamPCP Supply Chain Attack Compromises LiteLLM AI Package Used in 36% of Cloud Environments
Criminal group TeamPCP backdoored LiteLLM versions 1.82.7-1.82.8 on PyPI using compromised maintainer credentials. The package receives 3 million daily downloads and is present in 36% of cloud environments (Wiz Research). The malware extracted cloud credentials, API keys, and crypto wallets while installing a persistent downloader with a 50-minute heartbeat interval to evade sandbox detection. The attack is part of TeamPCP's broader campaign that has also hit Docker Hub, VS Code extensions, and the Trivy security scanner's CI/CD pipeline.
Analysis
LiteLLM's 36% cloud footprint and 3M daily downloads make this one of the most significant supply chain attacks of 2026. The 50-minute heartbeat interval is a sophistication marker; most commodity malware phones home immediately. TeamPCP's expansion from Trivy to Docker Hub, VS Code, and PyPI suggests a coordinated campaign against AI/developer tooling specifically, not opportunistic package compromise.
LiteLLM's 36% cloud footprint and 3M daily downloads make this one of the most significant supply chain attacks of 2026. The 50-minute heartbeat interval is a sophistication marker; most commodity malware phones home immediately. TeamPCP's expansion from Trivy to Docker Hub, VS Code, and PyPI suggests a coordinated campaign against AI/developer tooling specifically, not opportunistic package compromise.
1 sources
- Malicious LiteLLM versions linked to TeamPCP supply chain attack -
Security Affairs