TeamPCP Compromises LiteLLM PyPI Package, Steals Credentials

TeamPCP pushed credential-stealing malware into BerryAI's LiteLLM PyPI package (v1.82.7 and v1.82.8) on 2026-03-24. The malware collected SSH keys, cloud credentials, Kubernetes secrets, TLS keys and other secrets and established persistent backdoors for lateral movement. Both malicious releases were removed; v1.82.6 is the last known clean release.

Part of the PlainSec briefing for 2026-04-03

Sources