TeamPCP backdoors LiteLLM 1.82.7-1.82.8. Possible Trivy CI/CD compromise suspected.
Mar 24, 2026 // 22:33 - Tristan Wall


The hacker group TeamPCP, responsible for past issues with Trivy and KICS, has now infiltrated the popular Python package litellm. They introduced two harmful versions that include a tool to steal credentials, a means for moving laterally within Kubernetes, and a hidden backdoor for persistent access.

Security firms like Endor Labs and JFrog reported that versions 1.82.7 and 1.82.8 of litellm were released on March 24, 2026. This was likely due to the package’s CI/CD workflow using Trivy. Both of the infected versions have since been removed from the PyPI repository.

According to Endor Labs researcher Kiran Raj, “The attack occurs in three stages: first, a credential harvester gathers SSH keys, cloud credentials, Kubernetes secrets, cryptocurrency wallet information, and .env files. Second, a Kubernetes lateral movement toolkit deploys pods with elevated privileges to every node. Third, a systemd backdoor (sysmon.service) is established for persistent access, regularly checking ‘checkmarx[.]zone/raw’ for more malicious code.”

As seen in previous incidents, the compromised data is collected and sent as an encrypted file (“tpcp.tar.gz”) to a command-and-control server at “models.litellm[.]cloud” using HTTPS.

In version 1.82.7, the harmful code is located in the “litellm/proxy/proxy_server.py” file, having been inserted either during or after the package’s build process. The code is designed to run when the “litellm.proxy.proxy_server” module is imported, meaning any process importing it will trigger the malicious code without requiring any user action.

The updated iteration contains an even “more aggressive vector” by adding a malicious “litellm_init.pth” at the root of the package, which results in the malicious code being executed every time a Python process starts within the environment, not just when litellm is imported.

Another factor that makes version 1.82.8 more dangerous is that the .pth launcher creates a separate Python process using subprocess.Popen, enabling the malicious code to run in the background.

“Python .pth files that are placed in site-packages are automatically processed by site.py when the interpreter is started,” Endor Labs noted. “The file contains a single line that imports a subprocess and starts a detached Python process to decode and execute the same Base64-encoded malicious code.”

The decoded code acts as an orchestrator, unpacking a tool to steal credentials and a tool to ensure persistence. The credential harvester also uses the Kubernetes service account token (if available) to list all nodes in the cluster and deploy a pod with elevated privileges to each. The pod then chroots into the host’s file system and installs a persistence mechanism as a systemd user service on every node.

The systemd service is set up to run a Python script (“~/.config/sysmon/sysmon.py”) – the same name as in the Trivy incident – that connects to “checkmarx[.]zone/raw” every 50 minutes to get a URL for the next stage of the attack. If the URL contains youtube[.]com, the script stops running, which is a kill switch pattern seen in all of the incidents so far.

“This attack is likely ongoing,” according to Endor Labs. “TeamPCP’s pattern is consistent: each compromised environment provides credentials to access the next target. Moving from CI/CD (via GitHub Actions runners) to production (via PyPI packages running in Kubernetes) is a deliberate escalation.”

This latest incident means TeamPCP has been running a prolonged supply chain attack, impacting five environments, including GitHub Actions, Docker Hub, npm, Open VSX, and PyPI, to broaden its targets and gain control over more systems.

“TeamPCP is stepping up a coordinated attack, targeting security tools and open-source developer platforms, and is openly taking credit for related attacks across different environments,” Socket stated. “This is a sustained operation aimed at high-value points in the software supply chain.”

In a message posted on their Telegram channel, TeamPCP said: “These companies were built to protect your supply chains yet they can’t even protect their own, the state of modern security research is a joke, as a result we’re gonna be around for a long time stealing terrabytes [sic] of trade secrets with our new partners.”

“The snowball effect from this will be massive, we are already partnering with other teams to perpetuate the chaos, many of your favourite security tools and open-source projects will be targeted in the months to come so stay tuned,” the threat actor added.

Users are recommended to take the following actions to mitigate the threat –

  • Check all environments for litellm versions 1.82.7 or 1.82.8, and if found, revert to a clean version
  • Separate any affected hosts
  • Look for suspicious pods in Kubernetes clusters
  • Examine network logs for traffic going to “models.litellm[.]cloud” and “checkmarx[.]zone”
  • Remove the persistence mechanisms
  • Review CI/CD pipelines to see if tools like Trivy and KICS were used during the period of compromise
  • Invalidate and create new credentials for anything exposed

“The open source supply chain is collapsing in on itself,” said Gal Nagli, head of threat exposure at Google-owned Wiz, in a post on X. “Trivy gets compromised -> LiteLLM gets compromised -> credentials from tens of thousands of environments end up in attacker hands -> and those credentials lead to the next compromise. We are stuck in a loop.”

#1.82.7-1.82.8,  #backdoors  #ci/cd  #compromise  #litellm  #news  #possible  #suspected  #teampcp  #trivy   —   News