TeamPCP ha pubblicato versioni dannose del package BerryAI LiteLLM su PyPI (v1.82.7 e v1.82.8) il 24 marzo 2026. Le release esfiltravano SSH keys, cloud credentials, Kubernetes secrets e TLS keys e impiantavano backdoor persistenti per lateral movement.
Part of the PlainSec briefing for 2026-03-29
Every edition of this story: TeamPCP Inserisce Malware Rubacredenziali in LiteLLM