How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers

2026-04-06T13:24:15Z29b7b34d1fa5a1bcd418f00bde1273bcc8ac23a39e7bbe2aeba86f5e1b597e89
BYOVDaxios-compromisechrome-zero-dayciscocookie-controlled-webshells','php-web-shells','plugx','oauth-phscredential-harvestcve-2026-20093cve-2026-35616cve-2026-5281developer-workstationdprkdrift-hackedr-bypassfortinetios-darkswordnpm-malwareqilinransomwarereact2shellrevilsocial-engineeringsupply-chainunc1069vulnerable-driverwarlock

What happened

A broad set of high-impact incidents and active threats were reported, highlighting supply‑chain and social‑engineering compromises, large-scale credential theft, and multiple actively exploited vulnerabilities. Notable items include a supply‑chain attack leveraging developer workstations (LiteLLM/TeamPCP), a DPRK‑linked $285M exploit of Drift via a durable‑nonce social engineering campaign, ransomware groups Qilin and Warlock using BYOVD (vulnerable drivers) to disable 300+ EDR products, and 36 malicious npm packages posing as Strapi plugins to deploy implants and harvest secrets. Multiple 0‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
29b7b34d1fa5a1bcd418f00bde1273bcc8ac23a39e7bbe2aeba86f5e1b597e89
Enrichment time
2026-04-06T13:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.