Critical

TeamPCP supply chain attack hits LiteLLM PyPI package

SCM feed for Latest
Actively Exploited

Overview

The LiteLLM package, a popular open-source Python tool, has been compromised in a supply chain attack orchestrated by the TeamPCP group. They uploaded malicious versions of the package to the PyPI repository, which have since been taken down. This attack involves a three-stage process that starts with harvesting sensitive information like cloud credentials and cryptocurrency wallet details. It then escalates to deploying tools for lateral movement within Kubernetes environments and installing a persistent backdoor on affected systems. Researchers warn that this campaign is likely ongoing, as compromised systems can lead to further attacks on other environments, making it crucial for users to review their security measures.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: LiteLLM package on PyPI, Kubernetes environments
  • Action Required: Users should remove the malicious LiteLLM packages from their systems and audit their environments for any unauthorized access or installations.
  • Timeline: Newly disclosed

Original Article Summary

Widely used open-source Python package LiteLLM has been targeted by the TeamPCP threat operation to facilitate extensive data compromise as part of its Trivy supply chain attack campaign, reports The Hacker News. TeamPCP has published a pair of illicit LiteLLM packages, which have since been removed from the PyPI repository, to facilitate a three-stage intrusion commencing with the deployment of a credential harvester targeting cloud credentials, cryptocurrency wallets, and SSH keys, followed by the subsequent launches of a Kubernetes lateral movement toolkit and a persistent systemd backdoor, according to an analysis from Endor Labs. "This campaign is almost certainly not over. TeamPCP has demonstrated a consistent pattern: each compromised environment yields credentials that unlock the next target. The pivot from CI/CD (GitHub Actions runners) to production (PyPI packages running in Kubernetes clusters) is a deliberate escalation," said Endor Labs researchers.

Impact

LiteLLM package on PyPI, Kubernetes environments

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should remove the malicious LiteLLM packages from their systems and audit their environments for any unauthorized access or installations. Regularly updating dependencies and monitoring for unusual activity is also recommended.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News

Recent security research has revealed serious vulnerabilities in several popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could allow attackers to bypass authentication, take over accounts, and execute arbitrary code on affected sites. The most critical vulnerability, CVE-2026-76581, has a CVSS score of 9.8, indicating a high level of risk. Website owners using these plugins and themes are strongly advised to take immediate action to secure their sites, as the potential for exploitation is significant. Addressing these vulnerabilities is crucial to protect user data and maintain the integrity of web applications.

Aug 29, 2026

McKesson discloses breach after ShinyHunters claims patient data theft

BleepingComputer

McKesson, a major player in healthcare and pharmaceutical distribution, has reported a cybersecurity incident involving unauthorized access to its third-party applications. The ShinyHunters hacking group claims to have stolen an alarming 284 million patient records, raising serious concerns about data privacy and security in the healthcare sector. This breach could potentially expose sensitive information of millions of patients, emphasizing the vulnerability of healthcare systems to cyberattacks. As the situation develops, it is crucial for patients and healthcare providers to be aware of the implications, particularly regarding identity theft and the misuse of personal information. McKesson's disclosure serves as a stark reminder of the ongoing challenges faced by organizations in safeguarding their data against increasingly sophisticated cybercriminals.

Aug 28, 2026

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

The Hacker News

Berlin's state government has confirmed that it is facing an extortion attempt after hackers compromised the city's administrative network in August. The attackers have demanded a ransom, but officials have stated they will not pay. Forensic investigations have revealed additional data leaks, particularly affecting the Senate Department for Mobility, Transport, Climate Protection and Environment. This incident raises concerns about the security of public sector data and the potential risks of similar attacks on other cities and government entities. The refusal to pay may embolden attackers, while also highlighting the ongoing challenges of cybersecurity in public administration.

Aug 28, 2026

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

The Hacker News

Cosmos Labs has alerted users about a serious flaw in the Cosmos EVM module that allowed attackers to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, identified as GHSA-7g4w-cg88-2, is classified as Critical, yet it lacks a CVE identifier or CVSS score, which raises concerns about its management. This situation has left multiple blockchains at risk, as they were all vulnerable due to this shared module. The exploitation of this flaw not only resulted in financial losses but also poses broader implications for the security and trustworthiness of blockchain technologies. Users and developers on these affected blockchains need to be vigilant and consider taking immediate steps to safeguard their assets.

Aug 28, 2026

PaperCut releases second emergency patch for exploited flaws

BleepingComputer

PaperCut has issued a second emergency patch for its NG and MF print management software due to two vulnerabilities that are currently being exploited. Researchers found that there were ways to bypass the initial fixes provided in the first patch, which prompted the urgent release of this new update. Organizations using PaperCut's software should prioritize applying this patch to protect against potential attacks, as the vulnerabilities can lead to unauthorized access and exploitation. It’s critical for users to stay informed and ensure their systems are updated to mitigate these risks.

Aug 28, 2026

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News

Attackers are taking advantage of a recently patched vulnerability in PaperCut NG and MF software, allowing them to execute arbitrary code without needing authentication. This flaw gives unauthorized users remote access to the application's trusted configuration, which can be exploited to run Java code within the system. PaperCut has responded by releasing an emergency fix to address this issue and enhance security measures. Organizations using these PaperCut products should act quickly to apply the latest updates to safeguard their systems from potential exploitation. Failure to patch could leave systems vulnerable to significant security breaches.

Aug 28, 2026