
The hacking group TeamPCP, known for recently breaching Trivy and KICS, has now infiltrated a widely used Python package called litellm. They introduced two infected versions carrying a tool for stealing credentials, a means for moving around within Kubernetes systems, and a hidden backdoor for persistent access.
Security firms such as Endor Labs and JFrog have reported that litellm versions 1.82.7 and 1.82.8 were uploaded on March 24, 2026. This likely occurred because the package used Trivy in its CI/CD process. Both compromised versions have since been removed from PyPI.
According to Kiran Raj from Endor Labs, the malicious code operates in three stages: it first collects credentials such as SSH keys, cloud credentials, Kubernetes secrets, cryptocurrency wallet data, and .env files. Second, it uses a Kubernetes toolkit to deploy privileged pods on all nodes. Finally, it installs a persistent backdoor (sysmon.service) that regularly checks “checkmarx[.]zone/raw” for additional code.
As seen in previous attacks, the stolen data is compressed and encrypted into a file named “tpcp.tar.gz” and sent to a command-and-control server at “models.litellm[.]cloud” through an encrypted HTTPS connection.
In version 1.82.7, the malicious code resides in the “litellm/proxy/proxy_server.py” file, inserted either during or after the creation of the wheel package. The code is designed to run as soon as the “litellm.proxy.proxy_server” module is imported, meaning any process importing this module will trigger the malicious code without user interaction.
The subsequent version of the package includes a “more aggressive vector” by adding a malicious “litellm_init.pth” file at the wheel root. This forces the malicious code to execute automatically every time a Python process starts within the environment, not just when litellm is imported.
Version 1.82.8 is also more dangerous because the .pth launcher initiates a separate Python process using subprocess.Popen, enabling the malicious code to operate in the background.
Endor Labs explained that Python .pth files located in site-packages are automatically processed by site.py when the interpreter starts. The file contains a single line that imports a subprocess, launching a detached Python process to decode and run the same Base64-encoded malicious code.
The decoded code acts as an orchestrator, deploying both a credential harvester and a persistence installer. The harvester exploits the Kubernetes service account token (if available) to identify all nodes in the cluster and deploy a privileged pod onto each one. This pod then chroots into the underlying host file system, installing the persistence installer as a systemd user service on every node.
The systemd service is configured to execute a Python script (“~/.config/sysmon/sysmon.py”) â the same name used in the Trivy compromise. This script contacts “checkmarx[.]zone/raw” every 50 minutes to retrieve a URL that points to the next stage of the attack. The script contains a kill switch: if the URL includes youtube[.]com, it stops executing, which is a common pattern observed in all incidents thus far.
Endor Labs warns that the campaign is likely ongoing, stating that TeamPCP has a consistent strategy: compromising one environment to steal credentials, which then unlock the next target. They consider the move from CI/CD systems (GitHub Actions runners) to production systems (PyPI packages running in Kubernetes clusters) a deliberate escalation.
With this latest event, TeamPCP’s supply chain attack has now impacted five areas: GitHub Actions, Docker Hub, npm, Open VSX, and PyPI, broadening its reach and gaining control over an increasing number of systems.
Socket notes that TeamPCP is intensifying its coordinated attacks on security tools and open source development infrastructure, and is openly claiming responsibility for attacks across multiple ecosystems. They describe it as a sustained effort targeting key points in the software supply chain.
In a message on their Telegram channel, TeamPCP stated that companies built to protect supply chains cannot even protect themselves, dismissing modern security research as a joke. They claim that they will continue to steal terabytes of trade secrets with their partners.
The threat actor added that the snowball effect would be massive and that they are working with other groups to perpetuate the chaos, claiming that many popular security tools and open-source projects would be targeted in the coming months.
Users should take the following steps to mitigate the threat:
Gal Nagli, head of threat exposure at Wiz (owned by Google), commented on X that the open source supply chain is collapsing. He outlines a cycle of compromise: Trivy getting compromised leads to LiteLLM getting compromised, resulting in attacker access to credentials from many environments, which then leads to further compromises. He describes this as a continuous loop.
#1.82.7-1.82.8, #backdoors #breach #ci/cd #likely #litellm #news #teampcp #trivy #via — News
© Bulletproof Servers. All rights reserved.