Threats & Adversaries · Supply Chain

TeamPCP Injects Credential-Stealer into LiteLLM Package

TeamPCP published malicious telnyx versions 4.87.1 and 4.87.2 to PyPI that execute a credential-stealing backdoor when the SDK is imported. The backdoor targets Windows, Linux and macOS, harvests SSH keys, cloud tokens, wallets and environment secrets, and exfiltrates data to a TeamPCP-controlled endpoint. Attackers hid the payload inside WAV audio using runtime steganography; PyPI has quarantined the releases and 4.87.0 is the last known clean version.

12 sources · Apr 3

Timeline

Sources

Part of the PlainSec briefing for 2026-03-28

Every edition of this story: TeamPCP Injects Credential-Stealer into LiteLLM Package

More from today