Robuta

Sponsor of the Day: Jerkmate
https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/ LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign | Datadog... On March 24 and 27, 2026, malicious PyPI releases of LiteLLM and Telnyx were published as part of the TeamPCP supply chain campaign. We trace the full campaign... teampcp supply chainlitellmtelnyxcompromisedpypi https://www.infosecurity-magazine.com/news/teampcp-litellm-pypi-supply-chain/ TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise - Infosecurity Magazine Apr 9, 2026 - Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group supply chain campaignlitellm pypiinfosecurity magazineteampcpexpands https://it.slashdot.org/story/26/04/24/2032218/bitwarden-cli-is-the-next-compromise-in-checkmarx-supply-chain-campaign Bitwarden CLI Is the Next Compromise In Checkmarx Supply Chain Campaign - Slashdot Longtime Slashdot reader Himmy32 writes: Socket Security published an article on the compromise of the Bitwarden CLI client, which was pushed from Bitwarden's... checkmarx supply chainbitwarden clinextcompromisecampaign https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign Bitwarden CLI 2026.4.0 was compromised via GitHub Actions in Checkmarx campaign, exposing secrets and distributing malicious npm code checkmarx supply chainbitwarden clicompromisedongoingcampaign https://ramimac.me/teampcp/ Incident Timeline // TeamPCP Supply Chain Campaign Apr 7, 2026 - Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft. teampcp supply chainincidenttimelinecampaign https://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaign When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Campaign | SANS... Mar 26, 2026 - A trusted security scanner was weaponized. One stolen token cascaded across five ecosystems—CI/CD, npm, Docker, and AI infrastructure. The TeamPCP campaign... teampcp supply chainsecurity scannerbecameweaponinside https://securityboulevard.com/2026/04/bitwarden-cli-compromise-linked-to-ongoing-checkmarx-supply-chain-campaign/ Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign - Security Boulevard Apr 24, 2026 - While the attack on Bitwarden can be connected to the Checkmarx incident, it's unclear whether the same threat group is behind both. checkmarx supply chainbitwarden clisecurity boulevardcompromiselinked https://jamestown.org/prc-supply-chain-ecosystem-behind-irans-drone-campaign/ PRC Supply Chain Ecosystem Behind Iran's Drone Campaign - Jamestown supply chain ecosystembehind irandrone campaignprcjamestown