GeistHaus
log in · sign up

LiteLLM TeamPCP Supply Chain Attack: Malicious PyPI Packages | Wiz Blog

wiz.io

TeamPCP compromises LiteLLM, distributing malicious PyPI versions 1.82.7 and 1.82.8, using .pth files for stealthy persistence and data exfiltration.

2 pages link to this URL
Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.

2 inbound links en latest news latest newsexploits & vulnerabilitiesresearchcyber threatsthreatsartificial intelligence (ai)articlesnewsreports