TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise

2026-03-25T01:24:14Z1c18d760afdeb53a552a7ed917a1cd2350d34c47bb6bc1475c08a16b4048b1e7
BYOVDCanisterWormHwAudKillerScreenConnectTeamPCPactive-exploitationbackdoorcredential-harvestercritical-vulnerabilitiesgithub-actionsinfostealerkubernetes-lateral-movementlitellmmalvertisingnpm-malwarepython-packagesupply-chaintrivy

What happened

The Hacker News roundup highlights a wave of high-impact supply-chain and active-exploitation incidents. TeamPCP is tied to compromises of Trivy CI/CD and the litellm Python package (versions 1.82.7–1.82.8) that include credential harvesting, a Kubernetes lateral-movement toolkit, and a persistent backdoor; related follow-on activity has infected Docker images, hijacked npm packages (CanisterWorm) and abused GitHub Actions to steal CI/CD secrets. Separate large-scale campaigns include malvertising that delivers rogue ConnectWise ScreenConnect installers which drop HwAudKiller (BYOVD) to blindE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1c18d760afdeb53a552a7ed917a1cd2350d34c47bb6bc1475c08a16b4048b1e7
Enrichment time
2026-03-25T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.