TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise

2026-03-25T07:24:05Z4c7d0976d83a8566416c33b0a1b3dcff6b5abf7ca3b2e2dac6ddc675eb09fd53
BYOVDCISA/CVEsCanisterWormCheckmarxDocker HubGitHub ActionsHwAudKillerRCEScreenConnectTeamPCPTrivybackdoorcredential-theftlitellmmalvertisingnpm malwaresupply-chain

What happened

This collection highlights multiple high-impact supply-chain and large-scale malware incidents across developer and enterprise ecosystems. Key issues include TeamPCP compromising Trivy/KICS and publishing backdoored Python package litellm (v1.82.7–1.82.8) with credential harvesting, Kubernetes lateral-movement tooling and persistent backdoors; Trivy GitHub Actions compromise and Docker/ npm follow-on infections (including a self-propagating CanisterWorm); Checkmarx GitHub Actions breaches; and widespread malicious npm and PyPI/package abuse. Other notable threats: a malvertising campaign using

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4c7d0976d83a8566416c33b0a1b3dcff6b5abf7ca3b2e2dac6ddc675eb09fd53
Enrichment time
2026-03-25T07:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.