Minacce e avversari · Supply chain
Pacchetti LiteLLM compromessi esfiltravano segreti e installavano backdoor TeamPCP ha pubblicato su PyPI pacchetti BerryAI LiteLLM compromessi (v1.82.7 e v1.82.8) che rubano SSH keys, cloud tokens, Kubernetes secrets e TLS keys e installano backdoor persistenti. Le release dannose sono state rimosse e v1.82.6 è l'ultima release nota pulita. Fonti riportano che l'attore potrebbe aver esfiltrato oltre 300 GB e 500,000 credenziali. Questa operazione prende di mira tooling per sviluppatori e sicurezza per ottenere accesso elevato e permettere estorsioni successive.
12 fonti · 3 apr
Cronologia Fonti 3 apr Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
originale 31 mar Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
originale 30 mar Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
originale Part of the PlainSec briefing for 2026-04-01
Every edition of this story: Pacchetti LiteLLM compromessi esfiltravano segreti e installavano backdoor
Altro da oggi
Minacce e avversari · Supply chain
Pacchetti LiteLLM compromessi esfiltravano segreti e installavano backdoor TeamPCP ha pubblicato su PyPI pacchetti BerryAI LiteLLM compromessi (v1.82.7 e v1.82.8) che rubano SSH keys, cloud tokens, Kubernetes secrets e TLS keys e installano backdoor persistenti. Le release dannose sono state rimosse e v1.82.6 è l'ultima release nota pulita. Fonti riportano che l'attore potrebbe aver esfiltrato oltre 300 GB e 500,000 credenziali. Questa operazione prende di mira tooling per sviluppatori e sicurezza per ottenere accesso elevato e permettere estorsioni successive.
12 fonti · 3 apr
Cronologia Fonti 3 apr Dark Reading
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are creating a murky situation for enterprises.
originale 31 mar Unit 42
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
originale 30 mar Help Net Security
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP has shifted from supply chain expansion to monetization of existing credential harvests by partnering with ransomware attackers.
originale Part of the PlainSec briefing for 2026-04-01
Every edition of this story: Pacchetti LiteLLM compromessi esfiltravano segreti e installavano backdoor
Altro da oggi