Popular #LiteLLM #PyPI package #backdoored to steal #credentials , auth #tokens

The #TeamPCP #hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI & claiming to have stolen data from hundreds of thousands of devices during the attack.

LiteLLM is an open-source #Python library that serves as a gateway to multiple large language model ( #LLM ) providers via a single #API.
#privacy #security #supplychain

https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/

Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack

The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack.

BleepingComputer
Microsoft lays hands on login data: Beware of the new Outlook

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

heise online
another interesting detail with this SBT #military #crypto #device #backdoored by the #nsa is that it contains a weird virtual machine, this handles templating of messages and fixed point math, and uses only 2 data "registers" and a pointer register.

some interesting details, the #nsa #backdoored #phillips device runs a 8051 mcu. there's a print subroutine, that pops the return address from the stack, and prints the litteral chars from that address onwards until it finds a byte which has the top bit set. then it returns to the address after this last char. of course this is no calling-convention that any disassembler knows, so it throws them off.

2/n

The #NSA with the help of #philips #backdoored (again!) a european military messaging #device in the 80ies, a few years ago the fine people of the #cryptomuseum published everything they knew about it - including a #firmware dump:
https://www.cryptomuseum.com/crypto/philips/ua8295/

back then i #reverseEngineered this, and last week finally cleaned it up, and publish it today:

https://rad.ctrlc.hu/nodes/rad.ctrlc.hu/rad:z46AkAERuXAzqZcDRKvE7byRbkga1

also on the bad site: https://github.com/stef/UA-8295-NSA

update: it's a thread: 1/n

UA-8295

@tranquil_cassowary @halotroop2288 here's a good example:

https://www.criminaldefencelawyers.com.au/blog/possessing-dedicated-encrypted-criminal-communication-devices-laws-and-penalties-in-nsw/

And yes, this can and will be weaponized against any non-#Govware - #backdoored #OS & -Device.

In fact, #Australia banning #SecureDevices and -#Encryption came just after their #HoneyPot "#ANØM" aka. #OperationIronside aka. #OperationTrøjanShield had to end and they had to bust the users as #Estonia was unwilling to extend the permission to host the infrastructure on it's soil on behalf if #FBI & #AFP!

Possessing Dedicated Encrypted Criminal Communication Devices Laws and Penalties in NSW - Criminal Defence Lawyers Australia

The NSW Government has introduced new laws targeting the use and possession of encrypted devices used by criminals to evade law enforcement…

Criminal Defence Lawyers Australia

@stman @PrivacyDigest @theruran @50htz @vidak @forthy42 @oceane Again: #capitalism and.it's power structures as well as modalities incentivizes this #Centralization and #Enshittification.

  • Just like you see it with other #Businesses where you end up with monopolies, duopolies, tripolies or other oligopolies that subsequently shape #regulation through #lobbyism to basically make any new competition impossible.

That's why it's basically impossible to start an #MVNO, mich less a real mobile neteork and even less if you don't want to deploy #backdoored shite like #GSM / #3G / #4G / #5G but actually something that works.

@GossiTheDog Obviously this is nothing new, as #Microsoft's #CryptoAPI is so #backdoored that it's basically #Govware.

I'll be collecting apologies once the next #ToldYaSo hits.

thaddeus e. grugq on Twitter

“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”

Twitter

@ann3nova sadly this is nothing new.

The entire #CryptoAPI of #Windows is #backdoored for decades and #CensorBoot merely exists to prevent #Linux adoption and #DualBoot from working!