Threats & Adversaries · Supply Chain

TeamPCP Backdoors LiteLLM PyPI Package, Steals Credentials

TeamPCP pushed credential-stealing malware into BerryAI’s LiteLLM PyPI package (v1.82.7 and v1.82.8) on 24 March 2026. The malware harvested SSH keys, cloud credentials, Kubernetes secrets, TLS/private keys and other sensitive data and installed persistent backdoors enabling lateral movement.

12 sources · Apr 3

Timeline

Sources

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: TeamPCP Backdoors LiteLLM PyPI Package, Steals Credentials

More from today