TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
2026-03-25T07:24:05Z•4c7d0976d83a8566416c33b0a1b3dcff6b5abf7ca3b2e2dac6ddc675eb09fd53
BYOVDCISA/CVEsCanisterWormCheckmarxDocker HubGitHub ActionsHwAudKillerRCEScreenConnectTeamPCPTrivybackdoorcredential-theftlitellmmalvertisingnpm malwaresupply-chain
What happened
This collection highlights multiple high-impact supply-chain and large-scale malware incidents across developer and enterprise ecosystems. Key issues include TeamPCP compromising Trivy/KICS and publishing backdoored Python package litellm (v1.82.7–1.82.8) with credential harvesting, Kubernetes lateral-movement tooling and persistent backdoors; Trivy GitHub Actions compromise and Docker/ npm follow-on infections (including a self-propagating CanisterWorm); Checkmarx GitHub Actions breaches; and widespread malicious npm and PyPI/package abuse. Other notable threats: a malvertising campaign using
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4c7d0976d83a8566416c33b0a1b3dcff6b5abf7ca3b2e2dac6ddc675eb09fd53
- Enrichment time
- 2026-03-25T07:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.