Threats & Adversaries · Supply Chain
TeamPCP Injects Credential-Stealer into LiteLLM Package TeamPCP published malicious telnyx versions 4.87.1 and 4.87.2 to PyPI that execute a credential-stealing backdoor when the SDK is imported. The backdoor targets Windows, Linux and macOS, harvests SSH keys, cloud tokens, wallets and environment secrets, and exfiltrates data to a TeamPCP-controlled endpoint. Attackers hid the payload inside WAV audio using runtime steganography; PyPI has quarantined the releases and 4.87.0 is the last known clean version.
12 sources · Apr 3
Timeline Sources Apr 3 Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
original Apr 1 Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
original Mar 30 Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
original Part of the PlainSec briefing for 2026-03-28
Every edition of this story: TeamPCP Injects Credential-Stealer into LiteLLM Package
More from today
Threats & Adversaries · Supply Chain
TeamPCP Injects Credential-Stealer into LiteLLM Package TeamPCP published malicious telnyx versions 4.87.1 and 4.87.2 to PyPI that execute a credential-stealing backdoor when the SDK is imported. The backdoor targets Windows, Linux and macOS, harvests SSH keys, cloud tokens, wallets and environment secrets, and exfiltrates data to a TeamPCP-controlled endpoint. Attackers hid the payload inside WAV audio using runtime steganography; PyPI has quarantined the releases and 4.87.0 is the last known clean version.
12 sources · Apr 3
Timeline Sources Apr 3 Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
original Apr 1 Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
original Mar 30 Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
original Part of the PlainSec briefing for 2026-03-28
Every edition of this story: TeamPCP Injects Credential-Stealer into LiteLLM Package
More from today