TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise

TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor.
Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were published on March

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

Next Post

FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns

Related Posts
Total
0
Share