people · May 17, 2026
TeamPCP Supply Chain Campaign Compromised LiteLLM PyPI Versions 1.82.7 and 1.82.8
Share the canonical public link.
The TeamPCP group published malicious LiteLLM PyPI packages on March 24, 2026 as part of a broader supply chain campaign. Versions 1.82.7 and 1.82.8 included a .pth auto-execution payload that harvested credentials from approximately 97M monthly downloads at the time. The attack followed earlier compromises of Aqua Security Trivy and Checkmarx KICS and preceded the Checkmarx Jenkins plugin intrusion.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)