Il gruppo TeamPCP ha inserito malware per il furto di credenziali nelle release LiteLLM 1.82.7 e 1.82.8 pubblicate su PyPI il 24 marzo 2026. Il malware ha raccolto SSH key, cloud credentials (AWS, GCP, Azure), Kubernetes secrets e TLS/private keys. Le release malevole sono state rimosse da PyPI e la versione 1.82.6 è l'ultimo rilascio noto pulito.
Part of the PlainSec briefing for 2026-03-25
Every edition of this story: TeamPCP Compromette LiteLLM su PyPI e Ruba Credenziali