TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise
2026-03-25T01:24:14Z•1c18d760afdeb53a552a7ed917a1cd2350d34c47bb6bc1475c08a16b4048b1e7
BYOVDCanisterWormHwAudKillerScreenConnectTeamPCPactive-exploitationbackdoorcredential-harvestercritical-vulnerabilitiesgithub-actionsinfostealerkubernetes-lateral-movementlitellmmalvertisingnpm-malwarepython-packagesupply-chaintrivy
What happened
The Hacker News roundup highlights a wave of high-impact supply-chain and active-exploitation incidents. TeamPCP is tied to compromises of Trivy CI/CD and the litellm Python package (versions 1.82.7–1.82.8) that include credential harvesting, a Kubernetes lateral-movement toolkit, and a persistent backdoor; related follow-on activity has infected Docker images, hijacked npm packages (CanisterWorm) and abused GitHub Actions to steal CI/CD secrets. Separate large-scale campaigns include malvertising that delivers rogue ConnectWise ScreenConnect installers which drop HwAudKiller (BYOVD) to blindE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1c18d760afdeb53a552a7ed917a1cd2350d34c47bb6bc1475c08a16b4048b1e7
- Enrichment time
- 2026-03-25T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.