Threats & Adversaries · Supply Chain
Backdoored LiteLLM Packages Exfiltrated Secrets and Built Backdoors TeamPCP pushed backdoored BerryAI LiteLLM packages (v1.82.7 and v1.82.8) to PyPI that steal SSH keys, cloud tokens, Kubernetes secrets and TLS keys and install persistent backdoors. The malicious releases were removed and v1.82.6 is the last known clean release. Sources report the actor may have exfiltrated over 300 GB and 500,000 credentials. This operation targets developer and security tooling to gain elevated access and enable follow-on extortion.
12 sources · Apr 3
Timeline Sources Apr 3 Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
original Mar 31 Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
original Mar 30 Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
original Part of the PlainSec briefing for 2026-04-01
Every edition of this story: Backdoored LiteLLM Packages Exfiltrated Secrets and Built Backdoors
More from today
Threats & Adversaries · Supply Chain
Backdoored LiteLLM Packages Exfiltrated Secrets and Built Backdoors TeamPCP pushed backdoored BerryAI LiteLLM packages (v1.82.7 and v1.82.8) to PyPI that steal SSH keys, cloud tokens, Kubernetes secrets and TLS keys and install persistent backdoors. The malicious releases were removed and v1.82.6 is the last known clean release. Sources report the actor may have exfiltrated over 300 GB and 500,000 credentials. This operation targets developer and security tooling to gain elevated access and enable follow-on extortion.
12 sources · Apr 3
Timeline Sources Apr 3 Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
original Mar 31 Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
original Mar 30 Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
original Part of the PlainSec briefing for 2026-04-01
Every edition of this story: Backdoored LiteLLM Packages Exfiltrated Secrets and Built Backdoors
More from today