TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million Monthly Downloads on PyPI
Blog post from Endor Labs
On March 24, 2026, Endor Labs discovered that versions 1.82.7 and 1.82.8 of the popular open-source library litellm on PyPI contained malicious code not present in the original GitHub repository. This code included a backdoor that executed a hidden payload upon file import, with version 1.82.8 containing an additional .pth file that triggered the payload on any Python invocation, even when litellm was not directly imported. The payload executed a three-stage attack to steal credentials, move laterally across Kubernetes clusters, and install a persistent systemd backdoor, with the exfiltrated data being sent to an attacker-controlled domain. The attack vector and techniques used matched those of TeamPCP, a group known for targeting security-adjacent tools and ecosystems, aiming to gain access to environments rich in valuable credentials. The compromised litellm versions have been removed from PyPI, with version 1.82.6 being the last verified clean release.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 2 | 1,840 | 308 | 106 | +33% |
| LLM | 2 | 6,078 | 960 | 218 | +18% |
| Secrets Management | 2 | 1,488 | 268 | 99 | +7% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.