Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million Monthly Downloads on PyPI

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
683
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 24, 2026, Endor Labs discovered that versions 1.82.7 and 1.82.8 of the popular open-source library litellm on PyPI contained malicious code not present in the original GitHub repository. This code included a backdoor that executed a hidden payload upon file import, with version 1.82.8 containing an additional .pth file that triggered the payload on any Python invocation, even when litellm was not directly imported. The payload executed a three-stage attack to steal credentials, move laterally across Kubernetes clusters, and install a persistent systemd backdoor, with the exfiltrated data being sent to an attacker-controlled domain. The attack vector and techniques used matched those of TeamPCP, a group known for targeting security-adjacent tools and ecosystems, aiming to gain access to environments rich in valuable credentials. The compromised litellm versions have been removed from PyPI, with version 1.82.6 being the last verified clean release.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 2 1,840 308 106 +33%
LLM 2 6,078 960 218 +18%
Secrets Management 2 1,488 268 99 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.