How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM
CYBERSECURITY FEATURED ANALYSIS

How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD pipeline. …

On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD pipeline. Here’s what happened, how the three-stage malware works, and how to check if you’re affected.