Popular telnyx package compromised on PyPI by TeamPCP

The popular telnyx packageon PyPI, used by big AI companies, has been compromised by TeamPCP

This Week In Security: Second Verse, Worse Than The First

Isn’t there some claim events come in threes? After the extremely rare leak of the iOS Coruna exploit chain recently, now we have details from Google on a second significant exploit in the wi…

Hackaday

The LiteLLM Supply Chain Attack: How a Security Scanner Became a Backdoor

https://techlife.blog/posts/litellm-attack

#LiteLLM #SupplyChainAttack #PyPI #Security #Malware #Python #TeamPCP #AISecurity

The LiteLLM Supply Chain Attack: How a Security Scanner Became a Backdoor

On March 24, 2026, versions 1.82.7 and 1.82.8 of LiteLLM — with ~97 million monthly downloads — were found to contain a credential-stealing backdoor. Here's what happened, how it worked, and what you should do right now.

TechLife | AI, Software & Future Technology Insights

Preface: I accidently deleted the post I wrote. LMAO I was excited about an upcoming update to Coral Island and was miss-clicking like it was going out of style.

Oofta, this recent Python supply chain attack that was leveraged because of a stupid company, LiteLLM introducing an exploitable 15th standard; LiteLLM ended up giving malicious actors a juicy attack surface that they immediately leveraged.

Given the fact the oversight on LLM-pilled start-ups and corporations that peddle them is lacking...It's unsurprising that these malicious actors were able to enjoy a bit of success before being caught by happenstance.

Ah, I love watching these LLM-pilled companies getting fucked up like this.

The Primogen released a video about this matter and goes into greater detail. He's a great storyteller and I love listening to this dude regarding tech matters I don't fully understand.

https://youtu.be/mx3g7XoPVNQ

#FuckAI #SupplyChainAttack #Python

A bad day to use python

YouTube
A malicious LiteLLM package landed on PyPI with a solid plan: steal credentials, exfiltrate them, pivot through Kubernetes. Only problem? A bug in the payload caused it to fork-bomb itself on every Python subprocess. It never got past step one.
We walked through what would have happened if the malware had actually worked, and how sandboxing stops each stage. greyhaven.co/insights/how-greywall-prevents-every-stage-of-the-litellm-pypi-supply-chain-attack
#supplychainattack #sandboxing #infosec
LiteLLM Supply Chain Attack: What Happened, Who's Affected, and What You Should Do Right Now

LiteLLM — 95 million downloads per month, a dependency of CrewAI, DSPy, Browser-Use, Opik, and nearly every major AI agent framework — was hit by a supply chain attack. Here is what happened, how we responded, and what you should do right now.

Comet

[LiteLLM이 공급망 공격으로 해킹당했습니다.

LiteLLM이 공급망 공격으로 해킹당했으며, 1.82.8 및 1.82.7 버전이 영향을 받았다. 깃허브 이슈에서 스팸 봇 활동이 관찰되었으며, 해킹된 계정이 프로젝트 설명을 변경하는 등 이상 행위가 확인되었다.

https://news.hada.io/topic?id=27810

#cybersecurity #supplychainattack #opensource #github #hacking

LiteLLM이 공급망 공격으로 해킹당했습니다.

<p>https://github.com/BerriAI/litellm/issues/24512</p> <p>급하게 모바일로 쓰느라 제대로 마크다운으로 꾸미지 못하는 점 양해바랍니다.</p> <...

GeekNews
From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise

CrowdStrike discusses how this activity was discovered, how the attack works, what the payload does, and how to defend.

CrowdStrike.com
🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack #supplychainattack #security #AquaSecurity #HackerNews #ngated
Trivy Compromised by "TeamPCP" | Wiz Blog

Breaking down the March 2026 Trivy supply chain attack. TeamPCP compromised trivy + trivy-action & setup-trivy GitHub Actions, deploying credential stealers.

wiz.io