Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign
CYBERSECURITY FEATURED ANALYSIS

Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign

BY

James Haughom

SOURCE

Wiz Blog | RSS feed

DATE

READ

1 min read

LiteLLM is the latest victim of TeamPCP’s open-source attack spree. Malicious versions 1.82.7 and 1.82.8 abuse Python’s .pth mechanism for stealthy persistence. The malware exfiltrates cloud credentials, CI/CD secrets, …

LiteLLM is the latest victim of TeamPCP’s open-source attack spree. Malicious versions 1.82.7 and 1.82.8 abuse Python’s .pth mechanism for stealthy persistence. The malware exfiltrates cloud credentials, CI/CD secrets, and keys to attacker-controlled domains.